CVE-2016-5986
IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, 8.5.x before 8.5.5.11, 9.0.x before 9.0.0.2, and Liberty before 16.0.0.3 mishandles responses, which allows remote attackers to obtain sensitive information via…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.42%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, 8.5.x before 8.5.5.11, 9.0.x before 9.0.0.2, and Liberty before 16.0.0.3 mishandles responses, which allows remote attackers to obtain sensitive information via unspecified vectors.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.42% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ibm/websphere application server
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI67093Not Applicable
- http://www-01.ibm.com/support/docview.wss?uid=swg21990056Patch, Vendor Advisory
- http://www.securityfocus.com/bid/93013
- http://www.securitytracker.com/id/1036838
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI67093Not Applicable
- http://www-01.ibm.com/support/docview.wss?uid=swg21990056Patch, Vendor Advisory
- http://www.securityfocus.com/bid/93013
- http://www.securitytracker.com/id/1036838
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.