CVE-2016-0206Improper Input Validation in Corporation Cloud Orchestrator

Severity
3.3LOWNVD
EPSS
0.1%
top 83.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 8
Latest updateMay 17

Description

IBM Cloud Orchestrator could allow a local authenticated attacker to cause the server to slow down for a short period of time by using a specially crafted and malformed URL.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:LExploitability: 1.8 | Impact: 1.4

Affected Packages2 packages

NVDibm/cloud_orchestrator5 versions+4
CVEListV5ibm_corporation/cloud_orchestrator11 versions+10

Patches

🔴Vulnerability Details

2
GHSA
GHSA-r2x4-9wvq-fqx2: IBM Cloud Orchestrator could allow a local authenticated attacker to cause the server to slow down for a short period of time by using a specially cra2022-05-17
CVEList
CVE-2016-0206: IBM Cloud Orchestrator could allow a local authenticated attacker to cause the server to slow down for a short period of time by using a specially cra2017-02-08

🕵️Threat Intelligence

1
Talos
Vulnerability Spotlight: Redis CONFIG SET client-output-buffer-limit Code Execution Vulnerability2016-09-30

💬Community

1
Bugzilla
CVE-2016-8339 redis: OOB write vulnerability in handling of client-output-buffer-limit option during the CONFIG SET command2016-10-03
CVE-2016-0206 — Improper Input Validation | cvebase