CVE-2016-2996: Input Validation
Published Nov 24, 2016
·Updated
IBM Security Privileged Identity Manager 2.0 before 2.0.2 FP8, when Virtual Appliance is used, allows remote authenticated users to append to arbitrary files via unspecified vectors.
Affected Software
3 affected components
IBM Security Privileged Identity Manager=2.0.0
IBM Security Privileged Identity Manager=2.0.1
IBM Security Privileged Identity Manager=2.0.2
Event History
Nov 24, 2016
CVE Published
via MITRE·07:41 PM
Data Sourced
via MITRE·07:41 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-2996?
CVE-2016-2996 is considered a moderate severity vulnerability.
2
How do I fix CVE-2016-2996?
Upgrade IBM Security Privileged Identity Manager to version 2.0.2 FP8 or later to mitigate CVE-2016-2996.
3
Who is affected by CVE-2016-2996?
CVE-2016-2996 affects users of IBM Security Privileged Identity Manager versions prior to 2.0.2 FP8.
4
What kind of attack can exploit CVE-2016-2996?
CVE-2016-2996 can be exploited by remote authenticated users to append data to arbitrary files.
5
Is CVE-2016-2996 related to the Virtual Appliance of IBM Security Privileged Identity Manager?
Yes, CVE-2016-2996 specifically affects the Virtual Appliance deployment of IBM Security Privileged Identity Manager.