CVE-2016-9703: Low severity IBM Security Identity Manager Virtual Appliance vulnerability
IBM Security Identity Manager Virtual Appliance does not invalidate session tokens which could allow an unauthorized user with physical access to the work station to obtain sensitive information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9703?
CVE-2016-9703 has a moderate severity as it allows unauthorized access to sensitive information if session tokens are not invalidated.
How do I fix CVE-2016-9703?
To fix CVE-2016-9703, ensure that session tokens are invalidated after a user logs out or the session expires.
What versions of IBM Security Identity Manager Virtual Appliance are affected by CVE-2016-9703?
CVE-2016-9703 affects IBM Security Identity Manager Virtual Appliance versions 7.0.0.0 through 7.0.1.4.
Can physical access allow exploitation of CVE-2016-9703?
Yes, physical access to a workstation can allow an unauthorized user to exploit CVE-2016-9703 and obtain sensitive data.
Is there a patch available for CVE-2016-9703?
Yes, patches or updates may be available through IBM support for CVE-2016-9703 to address the vulnerability.