Lucene search

K
ibmIBM8F6C8825D0C0B61F79B5D0A5EC46A935F8BD6E6FBB906A51CA4AB61BE5386EA9
HistoryJun 15, 2018 - 7:07 a.m.

Security Bulletin: Weaker than expected security in IBM API Connect (CVE-2017-1386)

2018-06-1507:07:41
www.ibm.com
11

EPSS

0.001

Percentile

41.5%

Summary

IBM API Connect has addressed the following vulnerability which allows the possibility of bypassing password policy.

Vulnerability Details

CVEID:CVE-2017-1386**
DESCRIPTION: *IBM API Connect could allow a user to bypass policy restrictions and create non-compliant passwords which could be intercepted and decrypted using man in the middle techniques.
CVSS Base Score: 5.9
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/127160 for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Affected API Connect

|

Affected Versions

—|—
IBM API Connect| 5.0.0.0-5.0.7.1
IBM API Management| 4.0.0.0-4.0.4.5

Remediation/Fixes

Product

|

VRMF

|

APAR

|

Remediation / First Fix

—|—|—|—
IBM API Connect | 5.0.7.1| LI79690| APIConnect_Management

https://www-945.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%7EWebSphere&product=ibm/WebSphere/IBM+API+Connect&release=5.0.7.0&platform=All&function=all
IBM API Connect| 5.0.6.3| LI79690| APIConnect_Management

https://www-945.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%7EWebSphere&product=ibm/WebSphere/IBM+API+Connect&release=5.0.6.2&platform=All&function=all

IBM API Management| 4.0.4.6| LI79690| APIManagement-ManagementAppliance

http://www.ibm.com/support/fixcentral/swg/quickorder?parent=ibm%2FWebSphere%3C%2Fa%3E&product=ibm/WebSphere/IBM+API+Management&release=4.0.4.5&platform=All&function=fixId&fixids=4.0.4.6-APIManagement-AdvancedPortal-20170707-1023.ova,4.0.4.6-APIManagement-ManagementAppliance-20170706-1253_e11ee13f0a95.vcrypt2,4.0.4.6-APIManagement-AdvancedPortal-20170707-1023.sh,4.0.4.6-APIManagement-ManagementAppliance-20170706-1253_e11ee13f0a95.ova&includeSupersedes=0&source=fc

EPSS

0.001

Percentile

41.5%

Related for 8F6C8825D0C0B61F79B5D0A5EC46A935F8BD6E6FBB906A51CA4AB61BE5386EA9