CVE-2016-2960
IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.0.x before 8.0.0.13, 8.5.0.x before 8.5.5.10, 8.5.0.x and 16.0.0.x Liberty before Liberty Fix Pack 16.0.0.3, and 9.0.0.x before 9.0.0.1 allows remote attackers to cause a denial of service…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 39.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.0.x before 8.0.0.13, 8.5.0.x before 8.5.5.10, 8.5.0.x and 16.0.0.x Liberty before Liberty Fix Pack 16.0.0.3, and 9.0.0.x before 9.0.0.1 allows remote attackers to cause a denial of service via crafted SIP messages.
- CVSS 3.0
- 3.7 LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS
- 39.58% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- ibm/websphere application server
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI61548Broken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21984796Patch, Vendor Advisory
- http://www.securityfocus.com/bid/92354
- http://www.securitytracker.com/id/1036514
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI61548Broken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21984796Patch, Vendor Advisory
- http://www.securityfocus.com/bid/92354
- http://www.securitytracker.com/id/1036514
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.