First published: Thu Jul 27 2017(Updated: )
HTTP Parameter Override is identified in the IBM Infosphere Master Data Management (MDM) 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 product. It enables attackers by exposing the presence of duplicated parameters which may produce an anomalous behavior in the application that can be potentially exploited.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Master Data Management Collaborative Server | =10.1 | |
IBM InfoSphere Master Data Management Collaborative Server | =11.0 | |
IBM InfoSphere Master Data Management Collaborative Server | =11.3 | |
IBM InfoSphere Master Data Management Collaborative Server | =11.4 | |
IBM InfoSphere Master Data Management Collaborative Server | =11.5 | |
IBM InfoSphere Master Data Management Collaborative Server | =11.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9717 is considered a high severity vulnerability due to its potential for exploitation through HTTP Parameter Override.
To fix CVE-2016-9717, it is recommended to apply the latest patches provided by IBM for the affected versions of InfoSphere Master Data Management.
CVE-2016-9717 affects IBM InfoSphere Master Data Management versions 10.1, 11.0, 11.3, 11.4, 11.5, and 11.6.
CVE-2016-9717 allows attackers to exploit duplicated parameters in HTTP requests, potentially leading to anomalous behavior in the application.
Yes, CVE-2016-9717 is directly related to web application security as it deals with HTTP Parameter Override vulnerabilities.