4.3
CVE-2017-1107
- EPSS 0.35%
- Veröffentlicht 19.06.2019 14:15:10
- Zuletzt bearbeitet 21.11.2024 03:21:20
- Quelle psirt@us.ibm.com
- Teams Watchlist Login
- Unerledigt Login
IBM Marketing Platform 9.1.0, 9.1.2, 10.0, and 10.1 exposes sensitive information in the headers that could be used by an authenticated attacker in further attacks against the system. IBM X-Force ID: 120906.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Marketing Platform Version9.1.0.0
Ibm ≫ Marketing Platform Version9.1.2
Ibm ≫ Marketing Platform Version10.0
Ibm ≫ Marketing Platform Version10.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.35% | 0.547 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
psirt@us.ibm.com | 4.3 | 2.8 | 1.4 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.