VulnerabilityModified
CVE-2016-5990
IBM Security Privileged Identity Manager Virtual Appliance allows an authenticated user to upload malicious files that would be automatically executed by the server.
MEDIUM 6.3EPSS 0.64%
Does this matter?
Lower severity and a low EPSS score (0.64%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Security Privileged Identity Manager Virtual Appliance allows an authenticated user to upload malicious files that would be automatically executed by the server.
- CVSS 3.0
- 6.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- EPSS
- 0.64% probability · 49th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- ibm/security privileged identity manager
- Source
- psirt@us.ibm.com
References
- http://www.ibm.com/support/docview.wss?uid=swg21996614Patch, Vendor Advisory
- http://www.securityfocus.com/bid/95199Patch, VDB Entry
- http://www.ibm.com/support/docview.wss?uid=swg21996614Patch, Vendor Advisory
- http://www.securityfocus.com/bid/95199Patch, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.