Vulnerability Name: | CVE-2016-5959 (CCN-116136) | ||||||||||||
Assigned: | 2016-06-29 | ||||||||||||
Published: | 2017-06-02 | ||||||||||||
Updated: | 2017-06-13 | ||||||||||||
Summary: | IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 116136. | ||||||||||||
CVSS v3 Severity: | 5.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) 4.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
3.2 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-5959 Source: CCN Type: IBM Security Bulletin 2003092 (Security Privileged Identity Manager) Multiple Security vulnerabilities fixed in IBM Security Privileged Identity Manager Source: CONFIRM Type: Patch, Vendor Advisory http://www.ibm.com/support/docview.wss?uid=swg22003092 Source: BID Type: Third Party Advisory, VDB Entry 98829 Source: CCN Type: BID-98829 IBM Security Privileged Identity Manager CVE-2016-5959 Information Disclosure Vulnerability Source: MISC Type: VDB Entry, Vendor Advisory https://exchange.xforce.ibmcloud.com/vulnerabilities/116136 Source: XF Type: UNKNOWN ibm-spim-cve20165959-info-disc(116136) | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |