CVE-2016-5972: Infoleak
IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 uses weak permissions for unspecified resources, which allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5972?
CVE-2016-5972 is classified as a high severity vulnerability due to its potential to allow remote authenticated users to access sensitive information.
How do I fix CVE-2016-5972?
To fix CVE-2016-5972, upgrade IBM Security Privileged Identity Manager Virtual Appliance to version 2.0.2 FP8 or later.
What types of issues can CVE-2016-5972 cause?
CVE-2016-5972 can enable unauthorized users to obtain sensitive information and modify data due to weak permissions.
Which versions of IBM Security Privileged Identity Manager are affected by CVE-2016-5972?
CVE-2016-5972 affects all versions of IBM Security Privileged Identity Manager Virtual Appliance prior to 2.0.2 FP8.
Who can be impacted by CVE-2016-5972?
Remote authenticated users are impacted by CVE-2016-5972 due to the weak permissions allowing access to sensitive resources.