Sensitive Information Exposure in IBM Kenexa LCMS Premier on Cloud
CVE-2017-1143

5.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
27 March 2017

Summary

IBM Kenexa LCMS Premier on Cloud versions 9.x and 10.0 are susceptible to information exposure due to a misconfiguration of HTTP Strict Transport Security (HSTS). This flaw allows remote attackers to exploit man-in-the-middle techniques to intercept sensitive information transmitted between clients and the server. Proper implementation of HSTS is crucial for ensuring secure communication and protecting against data breaches. Organizations utilizing these affected versions should prioritize updates and remediation to mitigate potential security risks.

Affected Version(s)

Kenexa LCMS Premier on Cloud 9.0

Kenexa LCMS Premier on Cloud 9.1

Kenexa LCMS Premier on Cloud 9.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.