Sensitive Information Exposure in IBM Kenexa LCMS Premier on Cloud
CVE-2017-1143
What is CVE-2017-1143?
IBM Kenexa LCMS Premier on Cloud versions 9.x and 10.0 are susceptible to information exposure due to a misconfiguration of HTTP Strict Transport Security (HSTS). This flaw allows remote attackers to exploit man-in-the-middle techniques to intercept sensitive information transmitted between clients and the server. Proper implementation of HSTS is crucial for ensuring secure communication and protecting against data breaches. Organizations utilizing these affected versions should prioritize updates and remediation to mitigate potential security risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Kenexa LCMS Premier on Cloud 9.0
Kenexa LCMS Premier on Cloud 9.1
Kenexa LCMS Premier on Cloud 9.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved