SB2018030214 - Use of hard-coded credentials in IBM Rational Publishing Engine
Published: March 2, 2018 Updated: August 8, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Use of hard-coded credentials (CVE-ID: CVE-2017-1787)
The vulnerability allows a local privileged user to execute arbitrary code.
IBM Publishing Engine 2.1.2 and 6.0.5 contains an undisclosed vulnerability that could allow a local user with administrative privileges to obtain hard coded user credentials. IBM X-Force ID: 137022.
Remediation
Install update from vendor's website.