Vulnerability Name:

CVE-2016-0753 (CCN-110107)

Assigned:2015-12-16
Published:2016-01-25
Updated:2023-05-19
Summary:
CVSS v3 Severity:5.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
4.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2016-0753

Source: secalert@redhat.com
Type: Mailing List, Third Party Advisory
secalert@redhat.com

Source: secalert@redhat.com
Type: Mailing List, Third Party Advisory
secalert@redhat.com

Source: secalert@redhat.com
Type: Mailing List, Third Party Advisory
secalert@redhat.com

Source: secalert@redhat.com
Type: Mailing List, Third Party Advisory
secalert@redhat.com

Source: secalert@redhat.com
Type: Mailing List, Third Party Advisory
secalert@redhat.com

Source: secalert@redhat.com
Type: Mailing List, Third Party Advisory
secalert@redhat.com

Source: secalert@redhat.com
Type: Mailing List, Third Party Advisory
secalert@redhat.com

Source: CCN
Type: RHSA-2016-0296
Important: rh-ror41 security update

Source: secalert@redhat.com
Type: Third Party Advisory
secalert@redhat.com

Source: CCN
Type: Ruby on Rails Web Site
Rails 5.0.0.beta1.1, 4.2.5.1, 4.1.14.1, 3.2.22.1, and rails-html-sanitizer 1.0.3 have been released!

Source: secalert@redhat.com
Type: Third Party Advisory
secalert@redhat.com

Source: CCN
Type: IBM Security Bulletin 1979514 (BigFix family)
Multiple vulnerabilities in RubyOnRails affects IBM BigFix Compliance Analytics. (CVE-2015-7581, CVE-2016-0751, CVE-2016-0752, CVE-2016-0753)

Source: CCN
Type: IBM Security Bulletin 1985099 (License Metric Tool)
Security Bulletin: Vulnerabilities in Ruby on Rails affect IBM License Metric Tool v9, IBM BigFix Inventory v9 and IBM Endpoint Manager for Software Use Analysis v9 & v2.2

Source: secalert@redhat.com
Type: Mailing List, Third Party Advisory
secalert@redhat.com

Source: CCN
Type: BID-82247
Ruby on Rails Active Model CVE-2016-0753 Security Bypass Vulnerability

Source: secalert@redhat.com
Type: Broken Link, Third Party Advisory, VDB Entry
secalert@redhat.com

Source: secalert@redhat.com
Type: Broken Link, Third Party Advisory, VDB Entry
secalert@redhat.com

Source: XF
Type: UNKNOWN
rails-cve20160753-sec-bypass(110107)

Source: secalert@redhat.com
Type: Broken Link
secalert@redhat.com

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2016-0753

Vulnerable Configuration:Configuration CCN 1:
  • cpe:/a:rubyonrails:rails:3.0.0:-:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:license_metric_tool:9.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:license_metric_tool:9.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:license_metric_tool:9.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:license_metric_tool:9.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20160753
    V
    CVE-2016-0753
    2022-05-20
    oval:org.opensuse.security:def:55256
    P
    Security update for xen (Moderate)
    2021-10-07
    oval:org.opensuse.security:def:55940
    P
    Security update for openssl (Important)
    2021-08-24
    oval:org.opensuse.security:def:55939
    P
    Security update for python-PyYAML (Important)
    2021-08-24
    oval:org.opensuse.security:def:13880
    P
    libXtst6-1.2.2-3.59 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13899
    P
    libfreetype6-2.6.3-7.8.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13992
    P
    openvpn-2.3.8-16.6.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14745
    P
    python-doc-2.7.13-28.11.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14061
    P
    xen-4.7.0_12-23.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14017
    P
    python-libxml2-2.9.4-27.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14072
    P
    yast2-users-3.1.57-16.7 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14085
    P
    apache2-mod_jk-1.2.40-5.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14723
    P
    pam_ssh-2.0-1.39 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13816
    P
    evince-3.20.1-5.66 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13863
    P
    libHX28-3.18-1.18 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:38206
    P
    Security update for libsndfile (Critical)
    2021-07-27
    oval:org.opensuse.security:def:38116
    P
    Security update for curl (Moderate)
    2021-06-30
    oval:org.opensuse.security:def:38425
    P
    Security update for SUSE Manager Client Tools (Important)
    2021-06-21
    oval:org.opensuse.security:def:13726
    P
    squid-3.3.13-4.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:13748
    P
    wpa_supplicant-2.2-8.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:13718
    P
    rsyslog-8.4.0-8.3 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:38366
    P
    Security update for xorg-x11-server (Important)
    2021-04-13
    oval:org.opensuse.security:def:39265
    P
    Security update for openldap2 (Important)
    2021-03-04
    oval:org.opensuse.security:def:55257
    P
    Security update for python3 (Important)
    2021-02-08
    oval:org.opensuse.security:def:55773
    P
    Security update for mutt (Important)
    2020-12-07
    oval:org.opensuse.security:def:55774
    P
    Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP2) (Important)
    2020-12-07
    oval:org.opensuse.security:def:37821
    P
    ibus-chewing on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56498
    P
    Security update for libXcursor (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37726
    P
    apache-commons-beanutils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56332
    P
    Security update for rsync (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:39223
    P
    openconnect on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37958
    P
    libsmi on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56536
    P
    Security update for libqt4 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55116
    P
    gdm on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56425
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37725
    P
    ant on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56225
    P
    Security update for spice (Important)
    2020-12-01
    oval:org.opensuse.security:def:38059
    P
    rzsz on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56617
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56499
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:55095
    P
    dracut on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56333
    P
    Security update for procmail (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55494
    P
    Security update for libXfont (Important)
    2020-12-01
    oval:org.opensuse.security:def:56537
    P
    Recommended update for ucode-intel (Important)
    2020-12-01
    oval:org.opensuse.security:def:55117
    P
    gegl-0_2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55093
    P
    dnsmasq on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55667
    P
    Security update for libvirt (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56618
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:38474
    P
    rsyslog on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55495
    P
    Security update for xen (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38513
    P
    w3m on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55094
    P
    dosfstools on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55668
    P
    Security update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:38541
    P
    apache-commons-beanutils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37737
    P
    autofs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56424
    P
    Security update for mariadb (Important)
    2020-12-01
    oval:org.opensuse.security:def:56224
    P
    Security update for zlib (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38585
    P
    ecryptfs-utils on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.bionic:def:201607530000000
    V
    CVE-2016-0753 on Ubuntu 18.04 LTS (bionic) - medium.
    2016-02-16
    oval:com.ubuntu.xenial:def:201607530000000
    V
    CVE-2016-0753 on Ubuntu 16.04 LTS (xenial) - medium.
    2016-02-16
    oval:com.ubuntu.cosmic:def:201607530000000
    V
    CVE-2016-0753 on Ubuntu 18.10 (cosmic) - medium.
    2016-02-15
    oval:com.ubuntu.artful:def:20160753000
    V
    CVE-2016-0753 on Ubuntu 17.10 (artful) - medium.
    2016-02-15
    oval:com.ubuntu.trusty:def:20160753000
    V
    CVE-2016-0753 on Ubuntu 14.04 LTS (trusty) - medium.
    2016-02-15
    oval:com.ubuntu.bionic:def:20160753000
    V
    CVE-2016-0753 on Ubuntu 18.04 LTS (bionic) - medium.
    2016-02-15
    oval:com.ubuntu.xenial:def:20160753000
    V
    CVE-2016-0753 on Ubuntu 16.04 LTS (xenial) - medium.
    2016-02-15
    oval:com.ubuntu.cosmic:def:20160753000
    V
    CVE-2016-0753 on Ubuntu 18.10 (cosmic) - medium.
    2016-02-15
    oval:com.ubuntu.precise:def:20160753000
    V
    CVE-2016-0753 on Ubuntu 12.04 LTS (precise) - medium.
    2016-02-15
    BACK
    rubyonrails ruby on rails 3.0
    ibm license metric tool 9.0
    ibm license metric tool 9.0.1
    ibm license metric tool 9.1
    ibm license metric tool 9.2