SB2018022606 - Information disclosure in IBM Security Guardium Big Data Intelligence
Published: February 26, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Information disclosure (CVE-ID: CVE-2018-1377)
The vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability exists due to storing of user credentials in plain in clear text. A local attacker can gain access to potentially sensitive information.
2) Information disclosure (CVE-ID: CVE-2017-1774)
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to disclosure of sensitive information to unauthorized users. A remote attacker can gain access to potentially sensitive information and conduct further attacks.
Remediation
Install update from vendor's website.