CVE-2017-1785: Infoleak
Published Feb 7, 2018
·Updated
IBM API Connect 5.0.7 and 5.0.8 could allow an authenticated remote user to modify query parameters to obtain sensitive information. IBM X-Force ID: 136859.
Affected Software
5 affected components
IBM API Connect=5.0.7.0
IBM API Connect=5.0.7.1
IBM API Connect=5.0.7.2
IBM API Connect=5.0.8.0
IBM API Connect=5.0.8.1
Remediation
Patch Available
Event History
Feb 7, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-1785?
CVE-2017-1785 is considered a moderate severity vulnerability allowing an authenticated remote user to access sensitive information.
2
How do I fix CVE-2017-1785?
To mitigate CVE-2017-1785, upgrade your IBM API Connect to versions 5.0.7.3, 5.0.8.2 or later.
3
What versions of IBM API Connect are affected by CVE-2017-1785?
CVE-2017-1785 affects IBM API Connect versions 5.0.7.0, 5.0.7.1, 5.0.7.2, 5.0.8.0, and 5.0.8.1.
4
What type of attack does CVE-2017-1785 enable?
CVE-2017-1785 enables authenticated users to modify query parameters to retrieve sensitive data.
5
Is user authentication required to exploit CVE-2017-1785?
Yes, CVE-2017-1785 requires an authenticated remote user to exploit the vulnerability.