First published: Wed Feb 01 2017(Updated: )
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 stores potentially sensitive information in in log files that could be read by an authenticated user.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Kenexa LMS | =13.1 | |
IBM Kenexa LMS | =13.2 | |
IBM Kenexa LMS | =13.2.2 | |
IBM Kenexa LMS | =13.2.3 | |
IBM Kenexa LMS | =13.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8912 has a moderate severity rating due to the potential exposure of sensitive information in log files.
To fix CVE-2016-8912, apply the relevant patches or updates provided by IBM for the affected versions of Kenexa LMS on Cloud.
CVE-2016-8912 affects IBM Kenexa LMS on Cloud versions 13.1, 13.2, 13.2.2, 13.2.3, and 13.2.4.
CVE-2016-8912 poses a risk of exposing potentially sensitive information stored in log files that can be accessed by authenticated users.
Yes, exploitation of CVE-2016-8912 requires user authentication to access the log files containing the sensitive information.