CVE-2016-9703

CWE-3843 documents3 sources
Severity
2.4LOW
EPSS
0.1%
top 80.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 1
Latest updateMay 17

Description

IBM Security Identity Manager Virtual Appliance does not invalidate session tokens which could allow an unauthorized user with physical access to the work station to obtain sensitive information.

CVSS vector

CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 0.9 | Impact: 1.4

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-p2w6-gcfr-rq8g: IBM Security Identity Manager Virtual Appliance does not invalidate session tokens which could allow an unauthorized user with physical access to the2022-05-17
CVEList
CVE-2016-9703: IBM Security Identity Manager Virtual Appliance does not invalidate session tokens which could allow an unauthorized user with physical access to the2017-02-01
CVE-2016-9703 (LOW CVSS 2.4) | IBM Security Identity Manager Virtu | cvebase.io