PT-2017-12911 · Ibm · Daeja Viewone Virtual+2
Published
2017-07-13
·
Updated
2019-10-03
·
CVE-2017-1308
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Daeja ViewONE Professional, Standard & Virtual versions 4.1.5.1 and 5.0
Description
The issue is related to improper access controls, allowing an authenticated attacker to download files they should not have access to.
Recommendations
For version 4.1.5.1, update to a version that addresses the improper access controls issue.
For version 5.0, update to a version that addresses the improper access controls issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Daeja Viewone Professional
Daeja Viewone Standard
Daeja Viewone Virtual