CVE-2016-3043Sensitive Information Exposure in Corporation Access Manager

Severity
5.9MEDIUMNVD
EPSS
0.2%
top 56.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 1
Latest updateMay 13

Description

IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages1 packages

CVEListV5ibm_corporation/access_manager16 versions+15

Patches

🔴Vulnerability Details

2
GHSA
GHSA-58q7-57rm-wvx2: IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Stric2022-05-13
CVEList
CVE-2016-3043: IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Stric2017-02-01
CVE-2016-3043 — Sensitive Information Exposure | cvebase