Information Disclosure in IBM Integration Bus Affects User Credentials
CVE-2017-1694
8.1HIGH
Summary
IBM Integration Bus versions 9.0 and 10.0 are vulnerable due to the transmission of user credentials in clear text. This design flaw makes it possible for attackers to intercept sensitive information using man-in-the-middle techniques, potentially compromising user accounts and sensitive data. It underscores the need for secure transmission protocols in handling credentials to protect against unauthorized access and data breaches.
Affected Version(s)
Integration Bus 9.0
Integration Bus 10.0
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved