CVE-2017-1694

HIGH

IBM Integration Bus <10.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM Integration Bus 9.0 and 10.0 transmits user credentials in plain in clear text which can be read by an attacker using man in the middle techniques. IBM X-Force ID: 134165.

References (3)

Core 3
Core References
Vendor Advisory x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=swg22011695
VDB Entry, Vendor Advisory x_refsource_misc
https://exchange.xforce.ibmcloud.com/vulnerabilities/134165
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/102215

Scores

CVSS v3 8.1
EPSS 0.0081
EPSS Percentile 52.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-319
Status published
Products (22)
IBM/Integration Bus 10.0
IBM/Integration Bus 9.0
ibm/integration_bus 9.0.0.0
ibm/integration_bus 9.0.0.1
ibm/integration_bus 9.0.0.2
ibm/integration_bus 9.0.0.3
ibm/integration_bus 9.0.0.4
ibm/integration_bus 9.0.0.5
ibm/integration_bus 9.0.0.6
ibm/integration_bus 9.0.0.7
... and 12 more
Published Dec 20, 2017
Tracked Since Feb 18, 2026