CVE-2017-1731
Summary
| CVE | CVE-2017-1731 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-01-30 18:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security when using the Administrative Console. An authenticated remote attacker could exploit this vulnerability to possibly gain elevated privileges. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Websphere Application Server | All | All | All | All |
| Application | Ibm | Websphere Application Server | All | All | All | All |
| Application | Ibm | Websphere Application Server | All | All | All | All |
| Application | Ibm | Websphere Application Server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM WebSphere Application Server CVE-2017-1731 Remote Privilege Escalation Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| IBM WebSphere Application Server Flaw in Admin Console Lets Remote Authenticated Users Gain Elevated Privileges - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Security Bulletin: Potential Privilege Escalation in WebSphere Application Server Admin Console (CVE-2017-1731) | CONFIRM | www-01.ibm.com | Vendor Advisory |
| IBM X-Force Exchange | MISC | exchange.xforce.ibmcloud.com | VDB Entry, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.