VulnerabilityModified
CVE-2016-3022
IBM Security Access Manager for Web could allow an authenticated user to gain access to highly sensitive information due to incorrect file permissions.
MEDIUM 6.5EPSS 1.72%
Does this matter?
Lower severity and a low EPSS score (1.72%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Security Access Manager for Web could allow an authenticated user to gain access to highly sensitive information due to incorrect file permissions.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.72% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-275
- Affected
- ibm/security access manager 9.0 firmware · ibm/security access manager for mobile 8.0 firmware · ibm/security access manager for web 7.0 firmware · ibm/security access manager for web 8.0 firmware
- Source
- psirt@us.ibm.com
References
- http://www.ibm.com/support/docview.wss?uid=swg21995360Patch, Vendor Advisory
- http://www.securityfocus.com/bid/96130Third Party Advisory, VDB Entry
- http://www.ibm.com/support/docview.wss?uid=swg21995360Patch, Vendor Advisory
- http://www.securityfocus.com/bid/96130Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.