CVE-2016-0367: Infoleak
Published Feb 21, 2018
·Updated
IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 allows remote authenticated users to obtain sensitive information by reading an error message. IBM X-Force ID: 112072.
Affected Software
7 affected components
IBM Security Identity Manager Virtual Appliance=7.0.0.0
IBM Security Identity Manager Virtual Appliance=7.0.0.1
IBM Security Identity Manager Virtual Appliance=7.0.0.2
IBM Security Identity Manager Virtual Appliance=7.0.0.3
IBM Security Identity Manager Virtual Appliance=7.0.1.0
IBM Security Identity Manager Virtual Appliance=7.0.1.1
IBM Security Identity Manager Virtual Appliance=7.0.1.3
Remediation
Patch Available
Event History
Feb 21, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2016-0367.
2
What is the severity of CVE-2016-0367?
The severity of CVE-2016-0367 is medium (4.3).
3
Which software is affected by CVE-2016-0367?
IBM Security Identity Manager Virtual Appliance versions 7.0.x before 7.0.1.3-ISS-SIM-IF0001 are affected by CVE-2016-0367.
4
How can an authenticated user exploit CVE-2016-0367?
An authenticated user can exploit CVE-2016-0367 by reading an error message to obtain sensitive information.
5
Is there a fix available for CVE-2016-0367?
Yes, applying the IBM Security Identity Manager Virtual Appliance 7.0.1.3-ISS-SIM-IF0001 update fixes the vulnerability.