CVE-2016-3046: SQL Injection
Published Feb 1, 2017
·Updated
IBM Security Access Manager for Web is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements which could allow the attacker to view information in the back-end database.
Affected Software
9 affected components
IBM Security Access Manager For Web 8.0 Firmware
IBM Security Access Manager For Web Appliance=8.0
IBM Security Access Manager for Mobile
IBM Security Access Manager For Mobile Appliance=8.0
IBM Security Access Manager 9.0 Firmware
All of the following
IBM Security Access Manager For Web 8.0 Firmware
IBM Security Access Manager For Web Appliance=8.0
All of the following
IBM Security Access Manager for Mobile
IBM Security Access Manager For Mobile Appliance=8.0
Remediation
Patch Available
Event History
Feb 1, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Data Sourced
via NVD·08:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Dec 12, 58332
Event
10:35 AM
Frequently Asked Questions
1
What is the severity of CVE-2016-3046?
CVE-2016-3046 has a high severity level due to its potential for remote SQL injection attacks.
2
How do I fix CVE-2016-3046?
To fix CVE-2016-3046, apply the latest patches released by IBM for affected versions of IBM Security Access Manager for Web.
3
What systems are affected by CVE-2016-3046?
CVE-2016-3046 affects IBM Security Access Manager for Web version 8.0.
4
What could an attacker do if they exploit CVE-2016-3046?
An attacker exploiting CVE-2016-3046 could potentially view sensitive information stored in the back-end database.
5
Are there any workarounds for CVE-2016-3046?
There are no widely documented workarounds for CVE-2016-3046; the primary mitigation strategy is to apply the necessary updates.