CVE-2016-8925: Infoleak
Published Apr 14, 2017
·Updated
IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could allow a remote attacker to include arbitrary files which could allow the attacker to read any file on the system. IBM X-Force ID: 118538.
Affected Software
12 affected components
IBM Tivoli Application Dependency Discovery Manager=7.2.2
IBM Tivoli Application Dependency Discovery Manager=7.2.2.0
IBM Tivoli Application Dependency Discovery Manager=7.2.2.1
IBM Tivoli Application Dependency Discovery Manager=7.2.2.2
IBM Tivoli Application Dependency Discovery Manager=7.2.2.3
IBM Tivoli Application Dependency Discovery Manager=7.2.2.4
IBM Tivoli Application Dependency Discovery Manager=7.2.2.5
IBM Tivoli Application Dependency Discovery Manager=7.3.0
IBM Tivoli Application Dependency Discovery Manager=7.3.0.0
IBM Tivoli Application Dependency Discovery Manager=7.3.0.1
IBM Tivoli Application Dependency Discovery Manager=7.3.0.2
IBM Tivoli Application Dependency Discovery Manager=7.3.0.3
Remediation
Event History
Apr 14, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-8925?
CVE-2016-8925 has a medium severity rating which indicates a potential risk for data exposure.
2
Who is affected by CVE-2016-8925?
CVE-2016-8925 affects users of IBM Tivoli Application Dependency Discovery Manager versions 7.2.2 and 7.3.
3
How do I fix CVE-2016-8925?
To fix CVE-2016-8925, upgrade your IBM Tivoli Application Dependency Discovery Manager to the latest patched version provided by IBM.
4
What could an attacker achieve with CVE-2016-8925?
An attacker exploiting CVE-2016-8925 could potentially read arbitrary files on the system.
5
Is there a workaround for CVE-2016-8925?
Currently, there are no known workarounds for CVE-2016-8925; updating the software is recommended.