cbcvebase.
CVE-2016-0310
published 2017-02-08

CVE-2016-0310: IBM Connections 5.5 and earlier is vulnerable to possible host header injection attack that could cause navigation to the attacker's domain.

PriorityP426medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
0.52%
40.3th percentile
IBM Connections 5.5 and earlier is vulnerable to possible host header injection attack that could cause navigation to the attacker's domain.

Affected

11 ranges
VendorProductVersion rangeFixed in
ibmconnections
ibmconnections
ibmconnections
ibmconnections
ibm_corporationconnections
ibm_corporationconnections
ibm_corporationconnections
ibm_corporationconnections
ibm_corporationconnections
ibm_corporationconnections
ibm_corporationconnections

CVSS provenance

nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.