CVE-2016-0206: Input Validation
Published Feb 8, 2017
·Updated
IBM Cloud Orchestrator could allow a local authenticated attacker to cause the server to slow down for a short period of time by using a specially crafted and malformed URL.
Affected Software
5 affected components
IBM Cloud Orchestrator=2.3
IBM Cloud Orchestrator=2.3.0.1
IBM Cloud Orchestrator=2.4
IBM Cloud Orchestrator=2.4.0.1
IBM Cloud Orchestrator=2.4.0.2
Remediation
Patch Available
Event History
Feb 8, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Data Sourced
via NVD·10:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-0206?
The severity of CVE-2016-0206 is classified as a moderate risk due to its potential impact on server performance.
2
How do I fix CVE-2016-0206?
To fix CVE-2016-0206, upgrade to a patched version of IBM Cloud Orchestrator that addresses this vulnerability.
3
Who is affected by CVE-2016-0206?
CVE-2016-0206 affects users of IBM Cloud Orchestrator versions 2.3, 2.3.0.1, 2.4, 2.4.0.1, and 2.4.0.2.
4
What type of attack is CVE-2016-0206 associated with?
CVE-2016-0206 is associated with a local authenticated denial-of-service attack using a specially crafted URL.
5
Is CVE-2016-0206 a remote or local vulnerability?
CVE-2016-0206 is classified as a local vulnerability, requiring authenticated access to the server.