CVE-2017-1788
Low
Low
Medium
High
Critical
CVSS Score
Vulnerability Description
IBM WebSphere Application Server 9 installations using Form Login could allow a remote attacker to conduct spoofing attacks. IBM X-Force ID: 137031.
Known Affected Software
9 configuration(s) from 1 vendor(s)
websphere_application_server
Version:
9.0.0.0
CPE:
cpe:2.3:a:ibm:websphere_application_server:9.0.0.0:*:*:*:traditional:*:*:*
websphere_application_server
Version:
9.0.0.4
CPE:
cpe:2.3:a:ibm:websphere_application_server:9.0.0.4:*:*:*:*:*:*:*
websphere_application_server
Version:
9.0.0.5
CPE:
cpe:2.3:a:ibm:websphere_application_server:9.0.0.5:*:*:*:*:*:*:*
websphere_application_server
Version:
9.0.0.3
CPE:
cpe:2.3:a:ibm:websphere_application_server:9.0.0.3:*:*:*:*:*:*:*
websphere_application_server
Version:
9.0.0.6
CPE:
cpe:2.3:a:ibm:websphere_application_server:9.0.0.6:*:*:*:*:*:*:*
websphere_application_server
Version:
9.0.0.1
CPE:
cpe:2.3:a:ibm:websphere_application_server:9.0.0.1:*:*:*:*:*:*:*
websphere_application_server
Version:
9.0.0.7
CPE:
cpe:2.3:a:ibm:websphere_application_server:9.0.0.7:*:*:*:*:*:*:*
websphere_application_server
Version:
9.0
CPE:
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
websphere_application_server
Version:
9.0.0.2
CPE:
cpe:2.3:a:ibm:websphere_application_server:9.0.0.2:*:*:*:*:*:*:*
This vulnerability affects 9 software configuration(s). Ensure you patch all affected systems.
References & Resources
-
http://www.ibm.com/support/docview.wss?uid=swg22012341psirt@us.ibm.com Vendor Advisory
-
http://www.securityfocus.com/bid/103497psirt@us.ibm.com Third Party Advisory VDB Entry
-
https://exchange.xforce.ibmcloud.com/vulnerabilities/137031psirt@us.ibm.com VDB Entry Vendor Advisory
-
http://www.ibm.com/support/docview.wss?uid=swg22012341af854a3a-2127-422b-91ae-364da2661108 Vendor Advisory
-
http://www.securityfocus.com/bid/103497af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory VDB Entry
-
https://exchange.xforce.ibmcloud.com/vulnerabilities/137031af854a3a-2127-422b-91ae-364da2661108 VDB Entry Vendor Advisory
Severity Details
out of 10.0
Low
Key Information
- Published Date
- March 22, 2018
