CVE-2016-3024
published 2017-02-01CVE-2016-3024: IBM Security Access Manager for Web allows web pages to be stored locally which can be read by another user on the system.
PriorityP415medium4CVSS 3.0
AVLACLPRNUINSUCLINAN
EPSS
0.32%
24.1th percentile
IBM Security Access Manager for Web allows web pages to be stored locally which can be read by another user on the system.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | security_access_manager_9.0_firmware | — | — |
| ibm | security_access_manager_9.0_firmware | — | — |
| ibm | security_access_manager_9.0_firmware | — | — |
| ibm | security_access_manager_for_mobile_8.0_firmware | — | — |
| ibm | security_access_manager_for_mobile_8.0_firmware | — | — |
| ibm | security_access_manager_for_mobile_8.0_firmware | — | — |
| ibm | security_access_manager_for_mobile_8.0_firmware | — | — |
| ibm | security_access_manager_for_mobile_8.0_firmware | — | — |
| ibm | security_access_manager_for_mobile_8.0_firmware | — | — |
| ibm | security_access_manager_for_mobile_8.0_firmware | — | — |
| ibm | security_access_manager_for_mobile_8.0_firmware | — | — |
| ibm | security_access_manager_for_web_8.0_firmware | — | — |
| ibm | security_access_manager_for_web_8.0_firmware | — | — |
| ibm | security_access_manager_for_web_8.0_firmware | — | — |
| ibm | security_access_manager_for_web_8.0_firmware | — | — |
| ibm | security_access_manager_for_web_8.0_firmware | — | — |
| ibm | security_access_manager_for_web_8.0_firmware | — | — |
| ibm | security_access_manager_for_web_8.0_firmware | — | — |
| ibm | security_access_manager_for_web_8.0_firmware | — | — |
| ibm_corporation | access_manager | — | — |
| ibm_corporation | access_manager | — | — |
| ibm_corporation | access_manager | — | — |
| ibm_corporation | access_manager | — | — |
| ibm_corporation | access_manager | — | — |
| ibm_corporation | access_manager | — | — |
CVSS provenance
nvdv3.04.0MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3q74-6f83-38mg: IBM Security Access Manager for Web allows web pages to be stored locally which can be read by another user on the system
ghsa_unreviewed·2022-05-13
CVE-2016-3024 [MEDIUM] CWE-200 GHSA-3q74-6f83-38mg: IBM Security Access Manager for Web allows web pages to be stored locally which can be read by another user on the system
IBM Security Access Manager for Web allows web pages to be stored locally which can be read by another user on the system.
OSV
tomcat6, tomcat7, tomcat8 vulnerability
osv·2016-09-19·CVSS 7.8
CVE-2016-1240 tomcat6, tomcat7, tomcat8 vulnerability
tomcat6, tomcat7, tomcat8 vulnerability
Dawid Golunski discovered that the Tomcat init script incorrectly handled
creating log files. A remote attacker could possibly use this issue to
obtain root privileges. (CVE-2016-1240)
This update also reverts a change in behaviour introduced in USN-3024-1 by
setting mapperContextRootRedirectEnabled to True by default.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-02-01
Published