Information disclosure in IBM Business Process Manager - CVE-2017-1765

 

Information disclosure in IBM Business Process Manager - CVE-2017-1765

Published: April 8, 2018


Vulnerability identifier: #VU11620
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-1765
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to obtain potentially sensitive information on the target system.

The vulnerability exists due to unspecified error. A remote attacker can with "special privileges" can obtain potentially sensitive information about the target application server during snapshot export.


Affected software

IBM Business Process Manager
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
git-lfs (Red Hat package)

How to mitigate CVE-2017-1765

Install update from vendor's website.

git-lfs (Red Hat package) - update to 3.2.0-2.el8_8.1

External References

Related Security Bulletins