CVE-2016-3022: Medium severity IBM Security Access Manager 9.0 Firmware vulnerability
Published Feb 1, 2017
·Updated
IBM Security Access Manager for Web could allow an authenticated user to gain access to highly sensitive information due to incorrect file permissions.
Affected Software
76 affected components
IBM Security Access Manager 9.0 Firmware=9.0.0
IBM Security Access Manager 9.0 Firmware=9.0.0.1
IBM Security Access Manager 9.0 Firmware=9.0.1.0
IBM Security Access Manager For Mobile 8.0 Firmware=8.0.0.1
IBM Security Access Manager For Mobile 8.0 Firmware=8.0.0.2
IBM Security Access Manager For Mobile 8.0 Firmware=8.0.0.3
IBM Security Access Manager For Mobile 8.0 Firmware=8.0.0.5
IBM Security Access Manager For Mobile 8.0 Firmware=8.0.1.0
IBM Security Access Manager For Mobile 8.0 Firmware=8.0.1.2
IBM Security Access Manager For Mobile 8.0 Firmware=8.0.1.3
IBM Security Access Manager For Mobile 8.0 Firmware=8.0.1.4
IBM Security Access Manager For Web 7.0 Firmware=7.0.0.1
IBM Security Access Manager For Web 7.0 Firmware=7.0.0.2
IBM Security Access Manager For Web 7.0 Firmware=7.0.0.3
IBM Security Access Manager For Web 7.0 Firmware=7.0.0.4
IBM Security Access Manager For Web 7.0 Firmware=7.0.0.5
IBM Security Access Manager For Web 7.0 Firmware=7.0.0.6
IBM Security Access Manager For Web 7.0 Firmware=7.0.0.7
IBM Security Access Manager For Web 7.0 Firmware=7.0.0.8
IBM Security Access Manager For Web 7.0 Firmware=7.0.0.9
IBM Security Access Manager For Web 7.0 Firmware=7.0.0.10
IBM Security Access Manager For Web 7.0 Firmware=7.0.0.11
IBM Security Access Manager For Web 7.0 Firmware=7.0.0.12
IBM Security Access Manager For Web 7.0 Firmware=7.0.0.13
IBM Security Access Manager For Web 7.0 Firmware=7.0.0.14
IBM Security Access Manager For Web 7.0 Firmware=7.0.0.15
IBM Security Access Manager For Web 7.0 Firmware=7.0.0.16
IBM Security Access Manager For Web 8.0 Firmware=8.0.0.1
IBM Security Access Manager For Web 8.0 Firmware=8.0.0.2
IBM Security Access Manager For Web 8.0 Firmware=8.0.0.3
IBM Security Access Manager For Web 8.0 Firmware=8.0.0.5
IBM Security Access Manager For Web 8.0 Firmware=8.0.1.0
IBM Security Access Manager For Web 8.0 Firmware=8.0.1.2
IBM Security Access Manager For Web 8.0 Firmware=8.0.1.3
IBM Security Access Manager For Web 8.0 Firmware=8.0.1.4
IBM Security Access Manager For Mobile Appliance=8.0
IBM Security Access Manager For Web Appliance=7.0
IBM Security Access Manager For Web Appliance=8.0
All of the following
Any of the following
IBM Security Access Manager 9.0 Firmware=9.0.0
IBM Security Access Manager 9.0 Firmware=9.0.0.1
IBM Security Access Manager 9.0 Firmware=9.0.1.0
IBM Security Access Manager For Mobile 8.0 Firmware=8.0.0.1
IBM Security Access Manager For Mobile 8.0 Firmware=8.0.0.2
IBM Security Access Manager For Mobile 8.0 Firmware=8.0.0.3
IBM Security Access Manager For Mobile 8.0 Firmware=8.0.0.5
IBM Security Access Manager For Mobile 8.0 Firmware=8.0.1.0
IBM Security Access Manager For Mobile 8.0 Firmware=8.0.1.2
IBM Security Access Manager For Mobile 8.0 Firmware=8.0.1.3
IBM Security Access Manager For Mobile 8.0 Firmware=8.0.1.4
IBM Security Access Manager For Web 7.0 Firmware=7.0.0.1
IBM Security Access Manager For Web 7.0 Firmware=7.0.0.2
IBM Security Access Manager For Web 7.0 Firmware=7.0.0.3
IBM Security Access Manager For Web 7.0 Firmware=7.0.0.4
IBM Security Access Manager For Web 7.0 Firmware=7.0.0.5
IBM Security Access Manager For Web 7.0 Firmware=7.0.0.6
IBM Security Access Manager For Web 7.0 Firmware=7.0.0.7
IBM Security Access Manager For Web 7.0 Firmware=7.0.0.8
IBM Security Access Manager For Web 7.0 Firmware=7.0.0.9
IBM Security Access Manager For Web 7.0 Firmware=7.0.0.10
IBM Security Access Manager For Web 7.0 Firmware=7.0.0.11
IBM Security Access Manager For Web 7.0 Firmware=7.0.0.12
IBM Security Access Manager For Web 7.0 Firmware=7.0.0.13
IBM Security Access Manager For Web 7.0 Firmware=7.0.0.14
IBM Security Access Manager For Web 7.0 Firmware=7.0.0.15
IBM Security Access Manager For Web 7.0 Firmware=7.0.0.16
IBM Security Access Manager For Web 8.0 Firmware=8.0.0.1
IBM Security Access Manager For Web 8.0 Firmware=8.0.0.2
IBM Security Access Manager For Web 8.0 Firmware=8.0.0.3
IBM Security Access Manager For Web 8.0 Firmware=8.0.0.5
IBM Security Access Manager For Web 8.0 Firmware=8.0.1.0
IBM Security Access Manager For Web 8.0 Firmware=8.0.1.2
IBM Security Access Manager For Web 8.0 Firmware=8.0.1.3
IBM Security Access Manager For Web 8.0 Firmware=8.0.1.4
Any of the following
IBM Security Access Manager For Mobile Appliance=8.0
IBM Security Access Manager For Web Appliance=7.0
IBM Security Access Manager For Web Appliance=8.0
Remediation
Patch Available
Event History
Feb 1, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Data Sourced
via NVD·08:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-3022?
The severity of CVE-2016-3022 is classified as medium due to incorrect file permissions that could expose sensitive information.
2
How do I fix CVE-2016-3022?
To fix CVE-2016-3022, ensure that file permissions are correctly configured to restrict access to sensitive information.
3
Who is affected by CVE-2016-3022?
CVE-2016-3022 affects users of IBM Security Access Manager for Web versions 7.0 and 8.0, as well as IBM Security Access Manager for Mobile.
4
What is the impact of CVE-2016-3022?
The impact of CVE-2016-3022 may allow an authenticated user to access highly sensitive information due to incorrect file permissions.
5
When was CVE-2016-3022 reported?
CVE-2016-3022 was reported in 2016.