Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1110 CNY

100%

CVE-2017-1286

EPSS 0.20% · P42
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2017-1286

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Sensitive information about the configuration of the IBM UrbanCode Deploy 6.1 through 6.9.6.0 server and database can be obtained by a user who has been given elevated permissions in the UI, even after those elevated permissions have been revoked. IBM X-Force ID: 125147.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
IBM UrbanCode Deploy 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
IBM UrbanCode Deploy(UCD)是美国IBM公司的一套应用自动化部署工具。该工具基于一个应用部署自动化管理信息模型,并通过远程代理技术,实现对复杂应用在不同环境下的自动化部署等。 IBM UCD 6.1版本至6.9.6.0版本中存在安全漏洞。攻击者可借助在UI中提升的权限(即使权限被撤销)利用该漏洞获取有关服务器和数据库配置的敏感信息。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2017-1286

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-1286

登录查看更多情报信息。

Vendor Advisories for CVE-2017-1286 (2)

Same Patch Batch · n/a · 2018-08-13 · 15 CVEs total

CVE-2018-10569Edimax EW-7438RPn Mini 跨站脚本漏洞
CVE-2018-12587valeuraddons German Spelling Dictionary 跨站脚本漏洞
CVE-2018-13415Plex Media Server XML解析引擎安全漏洞
CVE-2018-13417Vuze Bittorrent Client XML解析引擎安全漏洞
CVE-2018-14849Tiki 跨站脚本漏洞
CVE-2018-14850Tiki 跨站脚本漏洞
CVE-2018-14878JetBrains dotPeek和ReSharper Ultimate 安全漏洞
CVE-2018-15139OpenEMR 安全漏洞
CVE-2018-15140OpenEMR 路径遍历漏洞
CVE-2018-15141OpenEMR 路径遍历漏洞
CVE-2018-15142OpenEMR 路径遍历漏洞
CVE-2018-15143OpenEMR SQL注入漏洞
CVE-2018-15144OpenEMR SQL注入漏洞
CVE-2018-15145OpenEMR SQL注入漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2017-1286

No comments yet


Leave a comment