Lucene search

K
cve[email protected]CVE-2017-1601
HistoryMay 02, 2018 - 1:29 p.m.

CVE-2017-1601

2018-05-0213:29:00
CWE-521
web.nvd.nist.gov
23
ibm
security guardium
database activity monitor
cve-2017-1601
password security
user account compromise
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

8.9 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

71.4%

IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 Database Activity Monitor does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 132624.

Affected configurations

NVD
Node
ibmsecurity_guardium_database_activity_monitorMatch10.0
OR
ibmsecurity_guardium_database_activity_monitorMatch10.0.1
OR
ibmsecurity_guardium_database_activity_monitorMatch10.1
OR
ibmsecurity_guardium_database_activity_monitorMatch10.1.2
OR
ibmsecurity_guardium_database_activity_monitorMatch10.1.3
OR
ibmsecurity_guardium_database_activity_monitorMatch10.1.4

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

8.9 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

71.4%

Related for CVE-2017-1601