Sensitive Information Exposure in IBM Kenexa LCMS Premier on Cloud
CVE-2017-1143
5.3MEDIUM
Summary
IBM Kenexa LCMS Premier on Cloud versions 9.x and 10.0 are susceptible to information exposure due to a misconfiguration of HTTP Strict Transport Security (HSTS). This flaw allows remote attackers to exploit man-in-the-middle techniques to intercept sensitive information transmitted between clients and the server. Proper implementation of HSTS is crucial for ensuring secure communication and protecting against data breaches. Organizations utilizing these affected versions should prioritize updates and remediation to mitigate potential security risks.
Affected Version(s)
Kenexa LCMS Premier on Cloud 9.0
Kenexa LCMS Premier on Cloud 9.1
Kenexa LCMS Premier on Cloud 9.2
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved