First published: Mon May 15 2017(Updated: )
IBM Distributed Marketing 8.6, 9.0, and 10.0 could allow a privileged authenticated user to create an instance that gets created with security profile not valid for the templates, that results in the new instance not accessible for the intended user. IBM X-Force ID: 116379.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Distributed Marketing | =8.6.0.0 | |
IBM Distributed Marketing | =8.6.0.2 | |
IBM Distributed Marketing | =8.6.0.3 | |
IBM Distributed Marketing | =8.6.0.4 | |
IBM Distributed Marketing | =8.6.0.5 | |
IBM Distributed Marketing | =8.6.0.6 | |
IBM Distributed Marketing | =8.6.0.7 | |
IBM Distributed Marketing | =8.6.0.8 | |
IBM Distributed Marketing | =8.6.0.9 | |
IBM Distributed Marketing | =8.6.0.10 | |
IBM Distributed Marketing | =9.1.0.0 | |
IBM Distributed Marketing | =9.1.0.2 | |
IBM Distributed Marketing | =9.1.0.3 | |
IBM Distributed Marketing | =9.1.0.4 | |
IBM Distributed Marketing | =9.1.0.5 | |
IBM Distributed Marketing | =9.1.0.6 | |
IBM Distributed Marketing | =9.1.0.7 | |
IBM Distributed Marketing | =9.1.0.8 | |
IBM Distributed Marketing | =9.1.0.9 | |
IBM Distributed Marketing | =9.1.0.10 | |
IBM Distributed Marketing | =9.1.0.11 | |
IBM Distributed Marketing | =9.1.2.0 | |
IBM Distributed Marketing | =9.1.2.1 | |
IBM Distributed Marketing | =9.1.2.2 | |
IBM Distributed Marketing | =9.1.2.3 | |
IBM Distributed Marketing | =10.0.0.0 | |
IBM Distributed Marketing | =10.0.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5979 is classified as a medium severity vulnerability allowing misconfiguration in the application instances.
To fix CVE-2016-5979, ensure that the created instances have valid security profiles that match the necessary templates.
CVE-2016-5979 affects users of IBM Distributed Marketing versions 8.6, 9.0, and 10.0.
CVE-2016-5979 is a vulnerability that allows privileged authenticated users to create instances with inappropriate security profiles.
As a temporary measure, validate the security profiles of instances created to ensure they meet the requirements before they are fully patched.