Input validation error in Network Data Loss Prevention (NDLP) - CVE-2017-4015

 

Input validation error in Network Data Loss Prevention (NDLP) - CVE-2017-4015

Published: August 3, 2023


Vulnerability identifier: #VU78904
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-4015
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote privileged user to modify data on the system.

The vulnerability exists due to insufficient validation of user-supplied input. A remote privileged user can pass specially crafted input to the application and modify data on the system.


Affected software

Network Data Loss Prevention (NDLP)
IBM TRIRIGA Application Platform

How to mitigate CVE-2017-4015

Install updates from vendor's website.

IBM TRIRIGA Application Platform - update to 4.5

External References

Related Security Bulletins