Lucene search

K
ibmIBM999097011EA7B8D1E180E2E31065D3063FD4E6CD8874B65A16133D85DD4248FB
HistoryJan 28, 2021 - 7:13 p.m.

Security Bulletin: Daeja ViewONE arbitrary files can be accessed

2021-01-2819:13:49
www.ibm.com
13
ibm
daeja viewone
access control

EPSS

0.001

Percentile

30.5%

Summary

IBM Daeja ViewONE Standard, Professional & Virtual could allow an authenticated attacker to download files they should not have access to due to improper access controls.

Vulnerability Details

CVEID:CVE-2017-1308 **DESCRIPTION:*IBM Daeja ViewONE Standard, Professional & Virtual could allow an authenticated attacker to download files they should not have access to due to improper access controls.
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/125462 for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N)

Affected Products and Versions

IBM Daeja ViewONE Standard, Professional & Virtual 4.1.5 - 4.1.5.1
IBM Daeja ViewONE Virtual 5.0

Remediation/Fixes

Product

| VRMF |Remediation
—|—|—
IBM Daeja ViewONE Standard, Professional & Virtual | 4.1.5 - 4.1.5.1 | Use IBM Daeja ViewONE 4.1.5.1ifix010 4.1.5.1_DAEJA_VIEWONE_IFIX010
IBM Daeja ViewONE Virtual | 5.0 | Use IBM Daeja ViewONE Virtual 5.0.0ifix010 5.0_DAEJA_VIEWONE_IFIX010

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

Subscribe to [My Notifications](< http://www-01.ibm.com/software/support/einfo.html&gt;) to be notified of important product support alerts like this.

References

Complete CVSS v2 Guide
On-line Calculator v2

Complete CVSS v3 Guide
On-line Calculator v3

Off

Related Information

IBM Secure Engineering Web Portal
IBM Product Security Incident Response Blog

Change History

July 12, 2017

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{“Line of Business”:{“code”:“LOB45”,“label”:“Automation”},“Business Unit”:{“code”:“BU053”,“label”:“Cloud & Data Platform”},“Product”:{“code”:“SSTTN8”,“label”:“IBM Daeja ViewONE Virtual”},“ARM Category”:[{“code”:“a8m0z0000001j5KAAQ”,“label”:“General News”}],“Platform”:[{“code”:“PF025”,“label”:“Platform Independent”}],“Version”:“5.0.0”},{“Line of Business”:{“code”:“LOB45”,“label”:“Automation”},“Business Unit”:{“code”:“BU053”,“label”:“Cloud & Data Platform”},“Product”:{“code”:“SSTTR7”,“label”:“IBM Daeja ViewONE Professional”},“ARM Category”:[{“code”:“a8m0z0000001j5KAAQ”,“label”:“General News”}],“Platform”:[{“code”:“PF025”,“label”:“Platform Independent”}],“Version”:“4.1.0”},{“Line of Business”:{“code”:“LOB36”,“label”:“IBM Automation”},“Business Unit”:{“code”:“BU053”,“label”:“Cloud & Data Platform”},“Product”:{“code”:“SS2S72”,“label”:“IBM Daeja ViewONE Standard”},“ARM Category”:[{“code”:“a8m0z0000001j5KAAQ”,“label”:“General News”}],“Platform”:[{“code”:“PF025”,“label”:“Platform Independent”}],“Version”:“4.1.0”}]

EPSS

0.001

Percentile

30.5%

Related for 999097011EA7B8D1E180E2E31065D3063FD4E6CD8874B65A16133D85DD4248FB