VulnerabilityModified
CVE-2016-3028
IBM Security Access Manager for Web 7.0 before IF2 and 8.0 before 8.0.1.4 IF3 and Security Access Manager 9.0 before 9.0.1.0 IF5 allow remote authenticated users to execute arbitrary commands by leveraging LMI admin access.
CRITICAL 9.1EPSS 3.54%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.54%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
IBM Security Access Manager for Web 7.0 before IF2 and 8.0 before 8.0.1.4 IF3 and Security Access Manager 9.0 before 9.0.1.0 IF5 allow remote authenticated users to execute arbitrary commands by leveraging LMI admin access.
- CVSS 3.0
- 9.1 CRITICALCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 3.54% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- ibm/security access manager · ibm/security access manager for web
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV89257Broken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV89322Broken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV89326Broken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21990317Vendor Advisory
- http://www.securityfocus.com/bid/93176
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV89257Broken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV89322Broken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV89326Broken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21990317Vendor Advisory
- http://www.securityfocus.com/bid/93176
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.