IBM Daeja ViewONE Standard, Professional & Virtual could allow an authenticated attacker to download files they should not have access to due to improper access controls.
CVEID:CVE-2017-1308 **DESCRIPTION:*IBM Daeja ViewONE Standard, Professional & Virtual could allow an authenticated attacker to download files they should not have access to due to improper access controls.
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/125462 for the current score
CVSS Environmental Score: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N)
IBM Daeja ViewONE Standard, Professional & Virtual 4.1.5 - 4.1.5.1
IBM Daeja ViewONE Virtual 5.0
Product
| VRMF |Remediation
—|—|—
IBM Daeja ViewONE Standard, Professional & Virtual | 4.1.5 - 4.1.5.1 | Use IBM Daeja ViewONE 4.1.5.1ifix010 4.1.5.1_DAEJA_VIEWONE_IFIX010
IBM Daeja ViewONE Virtual | 5.0 | Use IBM Daeja ViewONE Virtual 5.0.0ifix010 5.0_DAEJA_VIEWONE_IFIX010
None
Subscribe to [My Notifications](< http://www-01.ibm.com/software/support/einfo.html>) to be notified of important product support alerts like this.
Complete CVSS v2 Guide
On-line Calculator v2
Complete CVSS v3 Guide
On-line Calculator v3
Off
IBM Secure Engineering Web Portal
IBM Product Security Incident Response Blog
July 12, 2017
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
[{“Line of Business”:{“code”:“LOB45”,“label”:“Automation”},“Business Unit”:{“code”:“BU053”,“label”:“Cloud & Data Platform”},“Product”:{“code”:“SSTTN8”,“label”:“IBM Daeja ViewONE Virtual”},“ARM Category”:[{“code”:“a8m0z0000001j5KAAQ”,“label”:“General News”}],“Platform”:[{“code”:“PF025”,“label”:“Platform Independent”}],“Version”:“5.0.0”},{“Line of Business”:{“code”:“LOB45”,“label”:“Automation”},“Business Unit”:{“code”:“BU053”,“label”:“Cloud & Data Platform”},“Product”:{“code”:“SSTTR7”,“label”:“IBM Daeja ViewONE Professional”},“ARM Category”:[{“code”:“a8m0z0000001j5KAAQ”,“label”:“General News”}],“Platform”:[{“code”:“PF025”,“label”:“Platform Independent”}],“Version”:“4.1.0”},{“Line of Business”:{“code”:“LOB36”,“label”:“IBM Automation”},“Business Unit”:{“code”:“BU053”,“label”:“Cloud & Data Platform”},“Product”:{“code”:“SS2S72”,“label”:“IBM Daeja ViewONE Standard”},“ARM Category”:[{“code”:“a8m0z0000001j5KAAQ”,“label”:“General News”}],“Platform”:[{“code”:“PF025”,“label”:“Platform Independent”}],“Version”:“4.1.0”}]