Input validation error in Network Data Loss Prevention (NDLP) - CVE-2017-4015
Published: August 3, 2023
Vulnerability identifier: #VU78904
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-4015
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote privileged user to modify data on the system.
The vulnerability exists due to insufficient validation of user-supplied input. A remote privileged user can pass specially crafted input to the application and modify data on the system.
Affected software
Network Data Loss Prevention (NDLP)
IBM TRIRIGA Application Platform
IBM TRIRIGA Application Platform
How to mitigate CVE-2017-4015
Install updates from vendor's website.
IBM TRIRIGA Application Platform - update to 4.5