CVE-2017-1597
Last modified
CVE-2017-1597 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 Database Activity Monitor does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 132610.. EPSS estimates a 2.02% chance of exploitation in the next 30 days.
Description
IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 Database Activity Monitor does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 132610.
Metrics
CVSS:3.0/A:N/AC:H/AV:N/C:H/I:N/PR:N/S:U/UI:N/E:U/RC:C/RL:O
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Security Guardium | >= 10.0, <= 10.5 |
References
- http://www.securityfocus.com/bid/106236Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/132610VDB Entry, Vendor Advisory
- https://www.ibm.com/support/docview.wss?uid=swg22014231Vendor Advisory
- http://www.securityfocus.com/bid/106236Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/132610VDB Entry, Vendor Advisory
- https://www.ibm.com/support/docview.wss?uid=swg22014231Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-1597?
How severe is CVE-2017-1597?
How do I fix CVE-2017-1597?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-15964Job Board Script Software allows SQL Injection via the PATH_…
- CVE-2017-15965The NS Download Shop (aka com_ns_downloadshop) component 2.2…
- CVE-2017-15966The Zh YandexMap (aka com_zhyandexmap) component 6.1.1.0 for…
- CVE-2017-15967Mailing List Manager Pro 3.0 allows SQL Injection via the ed…
- CVE-2017-15968MyBuilder Clone 1.0 allows SQL Injection via the phpsqlsearc…
- CVE-2017-15969PG All Share Video 1.0 allows SQL Injection via the PATH_INF…
- CVE-2017-15970PHP CityPortal 2.0 allows SQL Injection via the nid paramete…
- CVE-2017-15971Same Sex Dating Software Pro 1.0 allows SQL Injection via th…9.8
- CVE-2017-15972SoftDatepro Dating Social Network 1.3 allows SQL Injection v…
- CVE-2017-15973Sokial Social Network Script 1.0 allows SQL Injection via th…
- CVE-2017-15974tPanel 2009 allows SQL injection for Authentication Bypass v…
- CVE-2017-15975Vastal I-Tech Dating Zone 0.9.9 allows SQL Injection via the…
Are you affected by CVE-2017-1597?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
