VulnerabilityModified
CVE-2016-9717
It enables attackers by exposing the presence of duplicated parameters which may produce an anomalous behavior in the application that can be potentially exploited.
MEDIUM 6.5EPSS 1.12%
Does this matter?
Lower severity and a low EPSS score (1.12%). Track it; it rarely justifies an emergency change on its own.
Description
HTTP Parameter Override is identified in the IBM Infosphere Master Data Management (MDM) 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 product. It enables attackers by exposing the presence of duplicated parameters which may produce an anomalous behavior in the application that can be potentially exploited.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 1.12% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- ibm/infosphere master data management server
- Source
- psirt@us.ibm.com
References
- http://www.ibm.com/support/docview.wss?uid=swg22006605Patch, Vendor Advisory
- http://www.securityfocus.com/bid/100074Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/119730VDB Entry, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg22006605Patch, Vendor Advisory
- http://www.securityfocus.com/bid/100074Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/119730VDB Entry, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.