{ "id": "CVE-2017-1731", "sourceIdentifier": "psirt@us.ibm.com", "published": "2018-01-30T18:29:00.223", "lastModified": "2019-10-03T00:03:26.223", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security when using the Administrative Console. An authenticated remote attacker could exploit this vulnerability to possibly gain elevated privileges." }, { "lang": "es", "value": "IBM WebSphere Application Server 7.0, 8.0, 8.5 y 9.0 podr\u00eda proporcionar seguridad m\u00e1s d\u00e9bil de la esperada al emplear la consola de administraci\u00f3n. Un atacante remoto autenticado podr\u00eda explotar esta vulnerabilidad para obtener privilegios elevados." } ], "metrics": { "cvssMetricV30": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH" }, "exploitabilityScore": 2.8, "impactScore": 5.9 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P", "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "SINGLE", "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "availabilityImpact": "PARTIAL", "baseScore": 6.5 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.0, "impactScore": 6.4, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "NVD-CWE-noinfo" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*", "versionStartIncluding": "7.0.0.0", "versionEndIncluding": "7.0.0.43", "matchCriteriaId": "98101B85-FFB7-4E21-AB44-9B8BE3ED9225" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*", "versionStartIncluding": "8.0.0.0", "versionEndIncluding": "8.0.0.14", "matchCriteriaId": "330E398A-A3EE-4546-A8CC-B1C77E5679E3" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*", "versionStartIncluding": "8.5.0.0", "versionEndIncluding": "8.5.5.13", "matchCriteriaId": "45BF11DE-674C-424E-9097-409F4967C612" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*", "versionStartIncluding": "9.0.0.0", "versionEndIncluding": "9.0.0.6", "matchCriteriaId": "A8A92B56-9F18-4720-900F-6E42FFC4E298" } ] } ] } ], "references": [ { "url": "http://www-01.ibm.com/support/docview.wss?uid=swg22012345&myns=swgws&mynp=OCSSEQTP&mync=R&cm_sp=swgws-_-OCSSEQTP-_-R", "source": "psirt@us.ibm.com", "tags": [ "Vendor Advisory" ] }, { "url": "http://www.securityfocus.com/bid/102911", "source": "psirt@us.ibm.com", "tags": [ "Third Party Advisory", "VDB Entry" ] }, { "url": "http://www.securitytracker.com/id/1040356", "source": "psirt@us.ibm.com", "tags": [ "Third Party Advisory", "VDB Entry" ] }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/134912", "source": "psirt@us.ibm.com", "tags": [ "VDB Entry", "Vendor Advisory" ] } ] }