First published: Fri Oct 06 2017(Updated: )
The Bi-directional driver in IDM 4.5 before 4.0.3.0 could be susceptible to unauthorized log configuration changes.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Microfocus Bi-directional Driver | <=4.0.2.0 | |
Micro Focus Identity Manager | =4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9273 is classified as a medium severity vulnerability due to its potential for unauthorized log configuration changes.
To fix CVE-2017-9273, update the Bi-directional driver to version 4.0.3.0 or later.
CVE-2017-9273 affects the Microfocus Bi-directional Driver versions up to and including 4.0.2.0.
Yes, CVE-2017-9273 can be exploited remotely if an attacker has access to the Bi-directional driver configuration.
Currently, there are no known workarounds for CVE-2017-9273, and applying the patch is the recommended solution.