CVE-2016-8923: Infoleak
IBM Curam Social Program Management 5.2, 6.0, and 7.0 contains a vulnerability that would allow an authorized user to obtain sensitive information from the profile of a higher privileged user that they should not have access to. IBM X-Force ID: 118536.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8923?
CVE-2016-8923 is considered a medium severity vulnerability due to the unauthorized access to sensitive information.
How do I fix CVE-2016-8923?
To fix CVE-2016-8923, users should apply the latest patches provided by IBM for their respective versions of IBM Curam Social Program Management.
Who is affected by CVE-2016-8923?
CVE-2016-8923 affects authorized users of IBM Curam Social Program Management versions 5.2, 6.0, 6.1, and 7.0.
What type of attack does CVE-2016-8923 enable?
CVE-2016-8923 enables an authorized user to access sensitive information from higher privileged user profiles.
Is there a workaround for CVE-2016-8923?
Currently, no official workaround exists for CVE-2016-8923; applying the appropriate patch is recommended.