Vulnerability Name: | CVE-2016-0231 (CCN-110299) | ||||||||||||
Assigned: | 2015-12-08 | ||||||||||||
Published: | 2016-02-12 | ||||||||||||
Updated: | 2016-03-10 | ||||||||||||
Summary: | IBM Financial Transaction Manager (FTM) for ACH Services, Check Services and Corporate Payment Services (CPS) 3.0.0 before FP12 allows remote authenticated users to obtain sensitive information by reading exception details in error logs. | ||||||||||||
CVSS v3 Severity: | 4.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N) 3.8 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-0231 Source: AIXAPAR Type: UNKNOWN PI56757 Source: AIXAPAR Type: UNKNOWN PI56758 Source: AIXAPAR Type: UNKNOWN PI56759 Source: AIXAPAR Type: UNKNOWN PI56762 Source: AIXAPAR Type: UNKNOWN PI56763 Source: AIXAPAR Type: UNKNOWN PI56764 Source: CONFIRM Type: Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21976392 Source: CCN Type: IBM Security Bulletin 1976392 (Financial Transaction Manager) IBM Financial Transaction Manager for ACH Services, Check Services and Corporate Payment Services: Information leakage and Access Control (CVE-2016-0231, CVE-2016-0232) Source: CCN Type: IBM Security Bulletin 1977224 (Financial Transaction Manager) Financial Transaction Manager for Corporate Payment Services Access Control: Information leakage in error handling (CVE-2016-0231 ) Source: XF Type: UNKNOWN ibm-ftm-cve20160231-info-disc(110299) | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
BACK |