CVE-2016-0307: Infoleak
Published Feb 8, 2017
·Updated
IBM Connections 5.5 and earlier allows remote attackers to obtain sensitive information by reading stack traces in returned responses.
Affected Software
4 affected components
IBM Connections=4.0.0.0
IBM Connections=4.5.0.0
IBM Connections=5.0.0.0
IBM Connections=5.5.0.0
Remediation
Patch Available
Event History
Feb 8, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Data Sourced
via NVD·10:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-0307?
CVE-2016-0307 is classified as a moderate severity vulnerability due to the exposure of sensitive information.
2
How do I fix CVE-2016-0307?
To fix CVE-2016-0307, update IBM Connections to a version later than 5.5.0.0 that includes security patches.
3
What types of systems are affected by CVE-2016-0307?
CVE-2016-0307 affects IBM Connections versions 4.0.0.0, 4.5.0.0, 5.0.0.0, and 5.5.0.0.
4
What kind of information can be leaked due to CVE-2016-0307?
CVE-2016-0307 may allow attackers to access sensitive stack trace information from responses.
5
Can CVE-2016-0307 be exploited remotely?
Yes, CVE-2016-0307 can be exploited remotely by attackers to retrieve sensitive information.