First published: Fri Feb 02 2018(Updated: )
IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 might allow remote attackers to access arbitrary JSP pages via vectors related to improper input validation. IBM X-Force ID: 111412.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM TRIRIGA Application Platform | =3.3.0.0 | |
IBM TRIRIGA Application Platform | =3.3.0.1 | |
IBM TRIRIGA Application Platform | =3.3.0.2 | |
IBM TRIRIGA Application Platform | =3.3.1.0 | |
IBM TRIRIGA Application Platform | =3.3.1.1 | |
IBM TRIRIGA Application Platform | =3.3.1.2 | |
IBM TRIRIGA Application Platform | =3.3.1.3 | |
IBM TRIRIGA Application Platform | =3.3.2.0 | |
IBM TRIRIGA Application Platform | =3.3.2.1 | |
IBM TRIRIGA Application Platform | =3.3.2.3 | |
IBM TRIRIGA Application Platform | =3.3.2.4 | |
IBM TRIRIGA Application Platform | =3.3.2.5 | |
IBM TRIRIGA Application Platform | =3.4.0.0 | |
IBM TRIRIGA Application Platform | =3.4.1.1 | |
IBM TRIRIGA Application Platform | =3.4.1.2 | |
IBM TRIRIGA Application Platform | =3.4.1.3 | |
IBM TRIRIGA Application Platform | =3.4.2.0 | |
IBM TRIRIGA Application Platform | =3.4.2.1 | |
IBM TRIRIGA Application Platform | =3.4.2.2 | |
IBM TRIRIGA Application Platform | =3.5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0300 has a medium severity rating, indicating a moderate level of risk for remote attacks.
To mitigate CVE-2016-0300, ensure that your IBM TRIRIGA Application Platform is updated to at least version 3.3.2.6, 3.4.2.3, or 3.5.0.1.
CVE-2016-0300 can be exploited by remote attackers to access arbitrary JSP pages due to improper input validation.
CVE-2016-0300 affects IBM TRIRIGA Application Platform versions 3.3 to 3.5, specifically before their patched releases.
Yes, additional information can be found in IBM's official vulnerability database and other security advisories.