PT-2017-12911 · Ibm · Daeja Viewone Virtual+2
Publicado
2017-07-13
·
Atualizado
2019-10-03
·
CVE-2017-1308
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Daeja ViewONE Professional, Standard & Virtual versions 4.1.5.1 and 5.0
Description
The issue is related to improper access controls, allowing an authenticated attacker to download files they should not have access to.
Recommendations
For version 4.1.5.1, update to a version that addresses the improper access controls issue.
For version 5.0, update to a version that addresses the improper access controls issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Files Accessible to External Parties
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Daeja Viewone Professional
Daeja Viewone Standard
Daeja Viewone Virtual