First published: Tue Jan 30 2018(Updated: )
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security when using the Administrative Console. An authenticated remote attacker could exploit this vulnerability to possibly gain elevated privileges.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Application Server Feature Pack for Web Services | >=7.0.0.0<=7.0.0.43 | |
IBM WebSphere Application Server Feature Pack for Web Services | >=8.0.0.0<=8.0.0.14 | |
IBM WebSphere Application Server Feature Pack for Web Services | >=8.5.0.0<=8.5.5.13 | |
IBM WebSphere Application Server Feature Pack for Web Services | >=9.0.0.0<=9.0.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-1731 is considered to be high due to potential privilege escalation risks.
To fix CVE-2017-1731, upgrade to the latest version of IBM WebSphere Application Server that is not affected by this vulnerability.
CVE-2017-1731 affects versions 7.0, 8.0, 8.5, and 9.0 of IBM WebSphere Application Server up to specific patch levels.
Yes, CVE-2017-1731 can be exploited by an authenticated remote attacker to gain elevated privileges.
Yes, exploitation of CVE-2017-1731 requires the attacker to be authenticated.