First published: Thu Nov 24 2016(Updated: )
IBM Security Privileged Identity Manager 2.0 before 2.0.2 FP8, when Virtual Appliance is used, allows remote authenticated users to append to arbitrary files via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Privileged Identity Manager | =2.0.0 | |
IBM Security Privileged Identity Manager | =2.0.1 | |
IBM Security Privileged Identity Manager | =2.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2996 is considered a moderate severity vulnerability.
Upgrade IBM Security Privileged Identity Manager to version 2.0.2 FP8 or later to mitigate CVE-2016-2996.
CVE-2016-2996 affects users of IBM Security Privileged Identity Manager versions prior to 2.0.2 FP8.
CVE-2016-2996 can be exploited by remote authenticated users to append data to arbitrary files.
Yes, CVE-2016-2996 specifically affects the Virtual Appliance deployment of IBM Security Privileged Identity Manager.