First published: Mon Mar 26 2018(Updated: )
IBM Security Privileged Identity Manager 2.1.0 contains left-over, sensitive information in page comments. While this information is not visible at first it can be obtained by viewing the page source. IBM X-Force ID: 134427.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Privileged Identity Manager Virtual Appliance | =2.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1705 is classified as a moderate severity vulnerability due to the presence of sensitive information in page comments.
To mitigate CVE-2017-1705, users should upgrade to a version of IBM Security Privileged Identity Manager that does not contain the sensitive information exposure.
CVE-2017-1705 specifically affects IBM Security Privileged Identity Manager version 2.1.0.
CVE-2017-1705 exposes left-over sensitive information within page comments that can be accessed through the page source.
There is currently no public information indicating that CVE-2017-1705 is being actively exploited in the wild.