CVE-2016-9739: High severity IBM Security Identity Manager vulnerability
Published Feb 1, 2017
·Updated
IBM Security Identity Manager Virtual Appliance stores user credentials in plain in clear text which can be read by a local user.
Affected Software
9 affected components
IBM Security Identity Manager=7.0.0.0
IBM Security Identity Manager=7.0.0.1
IBM Security Identity Manager=7.0.0.2
IBM Security Identity Manager=7.0.0.3
IBM Security Identity Manager=7.0.1.0
IBM Security Identity Manager=7.0.1.1
IBM Security Identity Manager=7.0.1.2
IBM Security Identity Manager=7.0.1.3
IBM Security Identity Manager=7.0.1.4
Remediation
Patch Available
Event History
Feb 1, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Data Sourced
via NVD·10:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-9739?
CVE-2016-9739 is rated as a medium severity vulnerability due to the exposure of user credentials.
2
How do I fix CVE-2016-9739?
To fix CVE-2016-9739, you should apply the latest patches provided by IBM for the affected versions of IBM Security Identity Manager.
3
Which versions are affected by CVE-2016-9739?
CVE-2016-9739 affects IBM Security Identity Manager versions 7.0.0.0 through 7.0.1.4.
4
What are the risks associated with CVE-2016-9739?
The risks associated with CVE-2016-9739 include unauthorized access to sensitive user credentials, which could lead to identity theft or data breaches.
5
Can CVE-2016-9739 be exploited remotely?
CVE-2016-9739 is primarily a local vulnerability, requiring local user access to exploit the stored credentials.