First published: Wed Feb 21 2018(Updated: )
IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 allows remote authenticated users to obtain sensitive information by reading an error message. IBM X-Force ID: 112072.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Identity Manager Virtual Appliance | =7.0.0.0 | |
IBM Security Identity Manager Virtual Appliance | =7.0.0.1 | |
IBM Security Identity Manager Virtual Appliance | =7.0.0.2 | |
IBM Security Identity Manager Virtual Appliance | =7.0.0.3 | |
IBM Security Identity Manager Virtual Appliance | =7.0.1.0 | |
IBM Security Identity Manager Virtual Appliance | =7.0.1.1 | |
IBM Security Identity Manager Virtual Appliance | =7.0.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2016-0367.
The severity of CVE-2016-0367 is medium (4.3).
IBM Security Identity Manager Virtual Appliance versions 7.0.x before 7.0.1.3-ISS-SIM-IF0001 are affected by CVE-2016-0367.
An authenticated user can exploit CVE-2016-0367 by reading an error message to obtain sensitive information.
Yes, applying the IBM Security Identity Manager Virtual Appliance 7.0.1.3-ISS-SIM-IF0001 update fixes the vulnerability.