CVE-2016-3040: Medium severity ibm security privileged identity manager virtual appliance vulnerability
IBM WebSphere Application Server (WAS) Liberty, as used in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8, allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3040?
CVE-2016-3040 has been classified as a medium severity vulnerability.
How do I fix CVE-2016-3040?
To fix CVE-2016-3040, update IBM Security Privileged Identity Manager Virtual Appliance to version 2.0.2 FP8 or later.
What type of attacks does CVE-2016-3040 allow?
CVE-2016-3040 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks.
Who is affected by CVE-2016-3040?
CVE-2016-3040 affects users of IBM Security Privileged Identity Manager Virtual Appliance version 2.0 prior to FP8.
Are there any workarounds for CVE-2016-3040?
Currently, the recommended solution for CVE-2016-3040 is to apply the specified updates, as no workarounds are provided.