CVE-2016-0323: Medium severity ibm bluemix vulnerability
Published May 17, 2016
·Updated
The Auto-Scaling agent in Liberty for Java in IBM Bluemix before 2.7-20160321-1358 allows remote authenticated users to disable X.509 certificate validation, and consequently bypass an intended HTTPS trust-management feature, via unspecified vectors.
Affected Software
1 affected component
IBM Bluemix
Event History
May 17, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-0323?
CVE-2016-0323 is classified as a medium severity vulnerability.
2
How do I fix CVE-2016-0323?
To fix CVE-2016-0323, ensure you update the IBM Bluemix service to the latest version that addresses this issue.
3
What does CVE-2016-0323 allow an attacker to do?
CVE-2016-0323 allows remote authenticated users to disable X.509 certificate validation, potentially compromising HTTPS trust management.
4
Which versions of IBM Bluemix are affected by CVE-2016-0323?
IBM Bluemix versions prior to 2.7-20160321-1358 are affected by CVE-2016-0323.
5
Is CVE-2016-0323 a local or remote vulnerability?
CVE-2016-0323 is a remote vulnerability that requires authenticated access to exploit.