CVE-2016-5971: Infoleak
IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5971?
CVE-2016-5971 is considered to have a medium severity rating due to the potential for unauthorized file access and denial of service.
How do I fix CVE-2016-5971?
To fix CVE-2016-5971, upgrade IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance to version 2.0.2 FP8 or later.
Who is affected by CVE-2016-5971?
CVE-2016-5971 affects remote authenticated users of IBM Security Privileged Identity Manager Virtual Appliance versions prior to 2.0.2 FP8.
What types of attacks can CVE-2016-5971 enable?
CVE-2016-5971 can enable attacks that lead to unauthorized access to files and potential denial of service due to memory consumption.
What is IBM Security Privileged Identity Manager Virtual Appliance?
IBM Security Privileged Identity Manager Virtual Appliance is a solution for managing and securing privileged accounts and credentials.