CVE-2016-3021

Severity
2.7LOW
EPSS
0.1%
top 77.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 1
Latest updateMay 13

Description

IBM Security Access Manager for Web could allow an authenticated attacker to obtain sensitive information from error message using a specially crafted HTTP request.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:NExploitability: 1.2 | Impact: 1.4

Affected Packages3 packages

NVDibm/security_access_manager24 versions+23
NVDibm/security_access_manager_9.0_firmware9.0.0, 9.0.0.1, 9.0.1.0+2
CVEListV5ibm_corporation/access_manager16 versions+15

🔴Vulnerability Details

2
GHSA
GHSA-g5m9-57rf-mghr: IBM Security Access Manager for Web could allow an authenticated attacker to obtain sensitive information from error message using a specially crafted2022-05-13
CVEList
CVE-2016-3021: IBM Security Access Manager for Web could allow an authenticated attacker to obtain sensitive information from error message using a specially crafted2017-02-01