ID

VAR-201702-0380


CVE

CVE-2016-3023


TITLE

IBM Security Access Manager Vulnerabilities that can gain access to important information

Trust: 0.8

sources: JVNDB: JVNDB-2016-007244

DESCRIPTION

IBM Security Access Manager for Web could allow an unauthenticated user to gain access to sensitive information by entering invalid file names. An attacker can exploit this issue to gain access to sensitive information; this may lead to further attacks. The product enables access management control through integrated appliances for web, mobile and cloud computing

Trust: 1.98

sources: NVD: CVE-2016-3023 // JVNDB: JVNDB-2016-007244 // BID: 96124 // VULHUB: VHN-91842

AFFECTED PRODUCTS

vendor:ibmmodel:security access manager for mobile 8.0scope:eqversion:8.0.1.0

Trust: 1.6

vendor:ibmmodel:security access manager for web 7.0scope:eqversion:7.0.0.2

Trust: 1.6

vendor:ibmmodel:security access manager for mobile 8.0scope:eqversion:8.0.0.3

Trust: 1.6

vendor:ibmmodel:security access manager for web 7.0scope:eqversion:7.0.0.15

Trust: 1.6

vendor:ibmmodel:security access manager for web 8.0scope:eqversion:8.0.1.3

Trust: 1.6

vendor:ibmmodel:security access manager for web 7.0scope:eqversion:7.0.0.13

Trust: 1.6

vendor:ibmmodel:security access manager for mobile 8.0scope:eqversion:8.0.0.2

Trust: 1.6

vendor:ibmmodel:security access manager for web 7.0scope:eqversion:7.0.0.14

Trust: 1.6

vendor:ibmmodel:security access manager for mobile 8.0scope:eqversion:8.0.1.2

Trust: 1.6

vendor:ibmmodel:security access manager for mobile 8.0scope:eqversion:8.0.0.5

Trust: 1.6

vendor:ibmmodel:security access manager 9.0scope:eqversion:9.0.1.0

Trust: 1.0

vendor:ibmmodel:security access manager for web 7.0scope:eqversion:7.0.0.12

Trust: 1.0

vendor:ibmmodel:security access manager for web 7.0scope:eqversion:7.0.0.6

Trust: 1.0

vendor:ibmmodel:security access manager for web 7.0scope:eqversion:7.0.0.16

Trust: 1.0

vendor:ibmmodel:security access manager for web 8.0scope:eqversion:8.0.1.0

Trust: 1.0

vendor:ibmmodel:security access manager for web 8.0scope:eqversion:8.0.0.3

Trust: 1.0

vendor:ibmmodel:security access manager for web 7.0scope:eqversion:7.0.0.3

Trust: 1.0

vendor:ibmmodel:security access manager for mobile 8.0scope:eqversion:8.0.0.1

Trust: 1.0

vendor:ibmmodel:security access manager 9.0scope:eqversion:9.0.0.1

Trust: 1.0

vendor:ibmmodel:security access manager 9.0scope:eqversion:9.0.0

Trust: 1.0

vendor:ibmmodel:security access manager for mobile 8.0scope:eqversion:8.0.1.4

Trust: 1.0

vendor:ibmmodel:security access manager for web 8.0scope:eqversion:8.0.0.5

Trust: 1.0

vendor:ibmmodel:security access manager for web 7.0scope:eqversion:7.0.0.7

Trust: 1.0

vendor:ibmmodel:security access manager for web 7.0scope:eqversion:7.0.0.1

Trust: 1.0

vendor:ibmmodel:security access manager for web 7.0scope:eqversion:7.0.0.8

Trust: 1.0

vendor:ibmmodel:security access manager for web 8.0scope:eqversion:8.0.0.2

Trust: 1.0

vendor:ibmmodel:security access manager for web 7.0scope:eqversion:7.0.0.11

Trust: 1.0

vendor:ibmmodel:security access manager for web 7.0scope:eqversion:7.0.0.4

Trust: 1.0

vendor:ibmmodel:security access manager for web 8.0scope:eqversion:8.0.1.2

Trust: 1.0

vendor:ibmmodel:security access manager for web 7.0scope:eqversion:7.0.0.5

Trust: 1.0

vendor:ibmmodel:security access manager for web 7.0scope:eqversion:7.0.0.10

Trust: 1.0

vendor:ibmmodel:security access manager for mobile 8.0scope:eqversion:8.0.1.3

Trust: 1.0

vendor:ibmmodel:security access manager for web 7.0scope:eqversion:7.0.0.9

Trust: 1.0

vendor:ibmmodel:security access manager for web 8.0scope:eqversion:8.0.0.1

Trust: 1.0

vendor:ibmmodel:security access manager for web 8.0scope:eqversion:8.0.1.4

Trust: 1.0

vendor:ibmmodel:security access manager for mobile the appliancescope: - version: -

Trust: 0.8

vendor:ibmmodel:security access manager for mobile softwarescope:eqversion:8.0

Trust: 0.8

vendor:ibmmodel:security access manager for web the appliancescope: - version: -

Trust: 0.8

vendor:ibmmodel:security access manager for web softwarescope:eqversion:7.0

Trust: 0.8

vendor:ibmmodel:security access manager for web softwarescope:eqversion:8.0

Trust: 0.8

vendor:ibmmodel:security access manager the appliancescope: - version: -

Trust: 0.8

vendor:ibmmodel:security access manager softwarescope:eqversion:9.0

Trust: 0.8

vendor:ibmmodel:security access manager for webscope:eqversion:8.0.1

Trust: 0.3

vendor:ibmmodel:security access manager for webscope:eqversion:8.03

Trust: 0.3

vendor:ibmmodel:security access manager for webscope:eqversion:8.02

Trust: 0.3

vendor:ibmmodel:security access manager for webscope:eqversion:8.0.1.4

Trust: 0.3

vendor:ibmmodel:security access manager for webscope:eqversion:8.0.1.3

Trust: 0.3

vendor:ibmmodel:security access manager for webscope:eqversion:8.0.1.2

Trust: 0.3

vendor:ibmmodel:security access manager for webscope:eqversion:8.0.1.1

Trust: 0.3

vendor:ibmmodel:security access manager for webscope:eqversion:8.0.1.0

Trust: 0.3

vendor:ibmmodel:security access manager for webscope:eqversion:8.0.0.5

Trust: 0.3

vendor:ibmmodel:security access manager for webscope:eqversion:8.0.0.4

Trust: 0.3

vendor:ibmmodel:security access manager for webscope:eqversion:8.0.0.0

Trust: 0.3

vendor:ibmmodel:security access manager for webscope:eqversion:8.0

Trust: 0.3

vendor:ibmmodel:security access manager for webscope:eqversion:7.0.0.9

Trust: 0.3

vendor:ibmmodel:security access manager for webscope:eqversion:7.0.0.8

Trust: 0.3

vendor:ibmmodel:security access manager for webscope:eqversion:7.0.0.7

Trust: 0.3

vendor:ibmmodel:security access manager for webscope:eqversion:7.0.0.6

Trust: 0.3

vendor:ibmmodel:security access manager for webscope:eqversion:7.0.0.5

Trust: 0.3

vendor:ibmmodel:security access manager for webscope:eqversion:7.0.0.4

Trust: 0.3

vendor:ibmmodel:security access manager for webscope:eqversion:7.0.0.3

Trust: 0.3

vendor:ibmmodel:security access manager for webscope:eqversion:7.0.0.2

Trust: 0.3

vendor:ibmmodel:security access manager for webscope:eqversion:7.0.0.16

Trust: 0.3

vendor:ibmmodel:security access manager for webscope:eqversion:7.0.0.15

Trust: 0.3

vendor:ibmmodel:security access manager for webscope:eqversion:7.0.0.14

Trust: 0.3

vendor:ibmmodel:security access manager for webscope:eqversion:7.0.0.13

Trust: 0.3

vendor:ibmmodel:security access manager for webscope:eqversion:7.0.0.12

Trust: 0.3

vendor:ibmmodel:security access manager for webscope:eqversion:7.0.0.11

Trust: 0.3

vendor:ibmmodel:security access manager for webscope:eqversion:7.0.0.10

Trust: 0.3

vendor:ibmmodel:security access manager for webscope:eqversion:7.0.0.1

Trust: 0.3

vendor:ibmmodel:security access manager for webscope:eqversion:7.0

Trust: 0.3

vendor:ibmmodel:security access manager for mobilescope:eqversion:8.0.1

Trust: 0.3

vendor:ibmmodel:security access manager for mobilescope:eqversion:8.0.1.4

Trust: 0.3

vendor:ibmmodel:security access manager for mobilescope:eqversion:8.0.1.3

Trust: 0.3

vendor:ibmmodel:security access manager for mobilescope:eqversion:8.0.1.2

Trust: 0.3

vendor:ibmmodel:security access manager for mobilescope:eqversion:8.0.1.1

Trust: 0.3

vendor:ibmmodel:security access manager for mobilescope:eqversion:8.0.0.5

Trust: 0.3

vendor:ibmmodel:security access manager for mobilescope:eqversion:8.0.0.4

Trust: 0.3

vendor:ibmmodel:security access manager for mobilescope:eqversion:8.0.0.3

Trust: 0.3

vendor:ibmmodel:security access manager for mobilescope:eqversion:8.0.0.2

Trust: 0.3

vendor:ibmmodel:security access manager for mobilescope:eqversion:8.0.0.1

Trust: 0.3

vendor:ibmmodel:security access manager for mobilescope:eqversion:8.0.0.0

Trust: 0.3

vendor:ibmmodel:security access manager for mobilescope:eqversion:8.0

Trust: 0.3

vendor:ibmmodel:security access managerscope:eqversion:9.0.1.0

Trust: 0.3

vendor:ibmmodel:security access managerscope:eqversion:9.0.0.1

Trust: 0.3

vendor:ibmmodel:security access managerscope:eqversion:9.0

Trust: 0.3

sources: BID: 96124 // JVNDB: JVNDB-2016-007244 // CNNVD: CNNVD-201702-060 // NVD: CVE-2016-3023

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2016-3023
value: MEDIUM

Trust: 1.0

NVD: CVE-2016-3023
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201702-060
value: MEDIUM

Trust: 0.6

VULHUB: VHN-91842
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2016-3023
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-91842
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2016-3023
baseSeverity: MEDIUM
baseScore: 5.3
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 1.4
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-91842 // JVNDB: JVNDB-2016-007244 // CNNVD: CNNVD-201702-060 // NVD: CVE-2016-3023

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.9

sources: VULHUB: VHN-91842 // JVNDB: JVNDB-2016-007244 // NVD: CVE-2016-3023

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201702-060

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201702-060

CONFIGURATIONS

sources: JVNDB: JVNDB-2016-007244

PATCH

title:1995348url:http://www-01.ibm.com/support/docview.wss?uid=swg21995348

Trust: 0.8

title:IBM Security Access Manager Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=67446

Trust: 0.6

sources: JVNDB: JVNDB-2016-007244 // CNNVD: CNNVD-201702-060

EXTERNAL IDS

db:NVDid:CVE-2016-3023

Trust: 2.8

db:BIDid:96124

Trust: 2.0

db:JVNDBid:JVNDB-2016-007244

Trust: 0.8

db:CNNVDid:CNNVD-201702-060

Trust: 0.7

db:VULHUBid:VHN-91842

Trust: 0.1

sources: VULHUB: VHN-91842 // BID: 96124 // JVNDB: JVNDB-2016-007244 // CNNVD: CNNVD-201702-060 // NVD: CVE-2016-3023

REFERENCES

url:http://www.securityfocus.com/bid/96124

Trust: 1.7

url:http://www.ibm.com/support/docview.wss?uid=swg21995348

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2016-3023

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2016-3023

Trust: 0.8

url:http://www.ibm.com/

Trust: 0.3

url:http://www-01.ibm.com/support/docview.wss?uid=swg21995348

Trust: 0.3

sources: VULHUB: VHN-91842 // BID: 96124 // JVNDB: JVNDB-2016-007244 // CNNVD: CNNVD-201702-060 // NVD: CVE-2016-3023

CREDITS

IBM X-Force Ethical Hacking Team: Paul Ionescu, Warren Moynihan, Jonathan Fitz-Gerald, John Zuccato, Rodney Ryan, Chris Shepherd, Dmitryi Beryoza.

Trust: 0.3

sources: BID: 96124

SOURCES

db:VULHUBid:VHN-91842
db:BIDid:96124
db:JVNDBid:JVNDB-2016-007244
db:CNNVDid:CNNVD-201702-060
db:NVDid:CVE-2016-3023

LAST UPDATE DATE

2024-11-23T22:59:25.679000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-91842date:2020-10-27T00:00:00
db:BIDid:96124date:2017-03-07T03:02:00
db:JVNDBid:JVNDB-2016-007244date:2017-02-16T00:00:00
db:CNNVDid:CNNVD-201702-060date:2020-10-28T00:00:00
db:NVDid:CVE-2016-3023date:2024-11-21T02:49:12.933

SOURCES RELEASE DATE

db:VULHUBid:VHN-91842date:2017-02-01T00:00:00
db:BIDid:96124date:2016-12-14T00:00:00
db:JVNDBid:JVNDB-2016-007244date:2017-02-16T00:00:00
db:CNNVDid:CNNVD-201702-060date:2017-02-06T00:00:00
db:NVDid:CVE-2016-3023date:2017-02-01T20:59:00.583