CVE-2017-1489

UnknownEPSS 1.18%

Last modified

CVE-2017-1489 is a vulnerability of currently unknown severity. IBM Security Access Manager 6.1, 7.0, 8.0, and 9.0 e-community configurations may be affected by a redirect vulnerability. ECSSO Master Authentication can redirect to a server not participating in an e-community domain. EPSS estimates a 1.18% chance of exploitation in the next 30 days.

Description

IBM Security Access Manager 6.1, 7.0, 8.0, and 9.0 e-community configurations may be affected by a redirect vulnerability. ECSSO Master Authentication can redirect to a server not participating in an e-community domain. IBM X-Force ID: 128687.

Metrics

EPSS Probability
1.18%

63.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
IbmTivoli Access Manager For E-Business6.1.0
IbmTivoli Access Manager For E-Business6.1.0.1
IbmTivoli Access Manager For E-Business6.1.0.2
IbmTivoli Access Manager For E-Business6.1.0.3
IbmTivoli Access Manager For E-Business6.1.0.4
IbmTivoli Access Manager For E-Business6.1.0.5
IbmTivoli Access Manager For E-Business6.1.0.6
IbmTivoli Access Manager For E-Business6.1.0.7
IbmTivoli Access Manager For E-Business6.1.0.8
IbmTivoli Access Manager For E-Business6.1.0.9
IbmTivoli Access Manager For E-Business6.1.0.10
IbmTivoli Access Manager For E-Business6.1.0.11
IbmTivoli Access Manager For E-Business6.1.0.12
IbmTivoli Access Manager For E-Business6.1.0.13
IbmTivoli Access Manager For E-Business6.1.0.14
IbmTivoli Access Manager For E-Business6.1.0.15
IbmTivoli Access Manager For E-Business6.1.0.16
IbmTivoli Access Manager For E-Business6.1.0.17
IbmTivoli Access Manager For E-Business6.1.0.18
IbmTivoli Access Manager For E-Business6.1.0.19
IbmTivoli Access Manager For E-Business6.1.0.20
IbmTivoli Access Manager For E-Business6.1.0.21
IbmTivoli Access Manager For E-Business6.1.0.22
IbmTivoli Access Manager For E-Business6.1.0.23
IbmTivoli Access Manager For E-Business6.1.0.24
IbmTivoli Access Manager For E-Business6.1.0.25
IbmTivoli Access Manager For E-Business6.1.0.26
IbmTivoli Access Manager For E-Business6.1.0.27
IbmTivoli Access Manager For E-Business6.1.0.28
IbmTivoli Access Manager For E-Business6.1.0.29
IbmTivoli Access Manager For E-Business6.1.0.30
IbmTivoli Access Manager For E-Business6.1.0.31
IbmTivoli Access Manager For E-Business6.1.1
IbmTivoli Access Manager For E-Business6.1.1.1
IbmTivoli Access Manager For E-Business6.1.1.2
IbmTivoli Access Manager For E-Business6.1.1.3
IbmTivoli Access Manager For E-Business6.1.1.4
IbmTivoli Access Manager For E-Business6.1.1.5
IbmTivoli Access Manager For E-Business6.1.1.6
IbmTivoli Access Manager For E-Business6.1.1.7
IbmTivoli Access Manager For E-Business6.1.1.8
IbmTivoli Access Manager For E-Business6.1.1.9
IbmTivoli Access Manager For E-Business6.1.1.10
IbmTivoli Access Manager For E-Business6.1.1.11
IbmTivoli Access Manager For E-Business6.1.1.12
IbmTivoli Access Manager For E-Business6.1.1.13
IbmTivoli Access Manager For E-Business6.1.1.14
IbmTivoli Access Manager For E-Business6.1.1.15
IbmTivoli Access Manager For E-Business6.1.1.16
IbmTivoli Access Manager For E-Business6.1.1.17

Showing 50 of 163 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-1489?
IBM Security Access Manager 6.1, 7.0, 8.0, and 9.0 e-community configurations may be affected by a redirect vulnerability. ECSSO Master Authentication can redirect to a server not participating in an e-community domain. IBM X-Force ID: 128687.
How severe is CVE-2017-1489?
Severity scoring for CVE-2017-1489 is pending analysis. The EPSS model estimates a 1.18% probability of exploitation in the next 30 days.
How do I fix CVE-2017-1489?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-1489?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST