{"api_version":"1","generated_at":"2026-07-23T05:24:07+00:00","cve":"CVE-2017-1731","urls":{"html":"https://cve.report/CVE-2017-1731","api":"https://cve.report/api/cve/CVE-2017-1731.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-1731","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-1731"},"summary":{"title":"CVE-2017-1731","description":"IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security when using the Administrative Console. An authenticated remote attacker could exploit this vulnerability to possibly gain elevated privileges.","state":"PUBLIC","assigner":"psirt@us.ibm.com","published_at":"2018-01-30 18:29:00","updated_at":"2019-10-03 00:03:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/bid/102911","name":"102911","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"IBM WebSphere Application Server CVE-2017-1731 Remote Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securitytracker.com/id/1040356","name":"1040356","refsource":"SECTRACK","tags":["Third Party Advisory","VDB Entry"],"title":"IBM WebSphere Application Server Flaw in Admin Console Lets Remote Authenticated Users Gain Elevated Privileges - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg22012345&myns=swgws&mynp=OCSSEQTP&mync=R&cm_sp=swgws-_-OCSSEQTP-_-R","name":"http://www-01.ibm.com/support/docview.wss?uid=swg22012345&myns=swgws&mynp=OCSSEQTP&mync=R&cm_sp=swgws-_-OCSSEQTP-_-R","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Security Bulletin: Potential Privilege Escalation in WebSphere Application Server Admin Console (CVE-2017-1731)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/134912","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/134912","refsource":"MISC","tags":["VDB Entry","Vendor Advisory"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-1731","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-1731","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"1731","vulnerable":"1","versionEndIncluding":"7.0.0.43","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"1731","vulnerable":"1","versionEndIncluding":"8.0.0.14","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"1731","vulnerable":"1","versionEndIncluding":"8.5.5.13","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"1731","vulnerable":"1","versionEndIncluding":"9.0.0.6","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"psirt@us.ibm.com","DATE_PUBLIC":"2018-01-29T00:00:00","ID":"CVE-2017-1731","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"WebSphere Application Server","version":{"version_data":[{"version_value":"9.0"},{"version_value":"7.0.0.35"},{"version_value":"7.0.0.37"},{"version_value":"7.0.0.39"},{"version_value":"7.0.0.41"},{"version_value":"7.0.0.43"},{"version_value":"8.0.0.4"},{"version_value":"8.0.0.5"},{"version_value":"8.0.0.6"},{"version_value":"8.0.0.7"},{"version_value":"8.0.0.8"},{"version_value":"8.0.0.9"},{"version_value":"8.0.0.10"},{"version_value":"8.0.0.11"},{"version_value":"8.0.0.12"},{"version_value":"8.0.0.13"},{"version_value":"8.0.0.14"},{"version_value":"8.5.5.7"},{"version_value":"8.5.5.8"},{"version_value":"8.5.5.9"},{"version_value":"8.5.5.10"},{"version_value":"8.5.5.11"},{"version_value":"8.5.5.12"},{"version_value":"9.0.0.1"},{"version_value":"9.0.0.2"},{"version_value":"9.0.0.3"},{"version_value":"9.0.0.4"},{"version_value":"9.0.0.5"},{"version_value":"9.0.0.6"}]}}]},"vendor_name":"IBM"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security when using the Administrative Console. An authenticated remote attacker could exploit this vulnerability to possibly gain elevated privileges."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Gain Privileges"}]}]},"references":{"reference_data":[{"name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/134912","refsource":"MISC","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/134912"},{"name":"http://www-01.ibm.com/support/docview.wss?uid=swg22012345&myns=swgws&mynp=OCSSEQTP&mync=R&cm_sp=swgws-_-OCSSEQTP-_-R","refsource":"CONFIRM","url":"http://www-01.ibm.com/support/docview.wss?uid=swg22012345&myns=swgws&mynp=OCSSEQTP&mync=R&cm_sp=swgws-_-OCSSEQTP-_-R"},{"name":"1040356","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1040356"},{"name":"102911","refsource":"BID","url":"http://www.securityfocus.com/bid/102911"}]}},"nvd":{"publishedDate":"2018-01-30 18:29:00","lastModifiedDate":"2019-10-03 00:03:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0.0.0","versionEndIncluding":"7.0.0.43","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*","versionStartIncluding":"8.0.0.0","versionEndIncluding":"8.0.0.14","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*","versionStartIncluding":"8.5.0.0","versionEndIncluding":"8.5.5.13","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*","versionStartIncluding":"9.0.0.0","versionEndIncluding":"9.0.0.6","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"1731","Ordinal":"97804","Title":"CVE-2017-1731","CVE":"CVE-2017-1731","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"1731","Ordinal":"1","NoteData":"IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security when using the Administrative Console. An authenticated remote attacker could exploit this vulnerability to possibly gain elevated privileges.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"1731","Ordinal":"2","NoteData":"2018-01-30","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"1731","Ordinal":"3","NoteData":"2018-02-09","Type":"Other","Title":"Modified"}]}}}