First published: Wed Feb 21 2018(Updated: )
IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 might allow remote attackers to obtain sensitive information by leveraging weak encryption. IBM X-Force ID: 112071.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Privileged Identity Manager Virtual Appliance | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-0366 is rated as medium due to the potential for remote attackers to gain access to sensitive information.
To fix CVE-2016-0366, you should upgrade to IBM Security Identity Manager Virtual Appliance version 7.0.1.3-ISS-SIM-IF0001 or later.
CVE-2016-0366 affects IBM Security Identity Manager Virtual Appliance versions prior to 7.0.1.3-ISS-SIM-IF0001.
Yes, CVE-2016-0366 can be exploited remotely by leveraging weak encryption.
CVE-2016-0366 is categorized as an information disclosure vulnerability due to its weak encryption affecting sensitive data.