Lucene search

K
ibmIBM31B2B5A736EA4B57F6B75FDB5266E8388F33501613A67FFF28D286D1BBC71B2A
HistoryJun 17, 2018 - 3:21 p.m.

Security Bulletin: Information disclosure through unauthenticated SOAP request message. (CVE-2016-0299)

2018-06-1715:21:33
www.ibm.com
10

0.001 Low

EPSS

Percentile

43.5%

Summary

IBM TRIRIGA could disclose sensitive information using a query to the IBM TRIRIGA platform database using crafted web service request by means of a HTTP / SOAP query.

Vulnerability Details

CVEID: CVE-2016-0299
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/111382 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

The following IBM TRIRIGA Application Platform versions are affected.
ยท IBM TRIRIGA Application Platform 3.5.
ยท IBM TRIRIGA Application Platform 3.4.
ยท IBM TRIRIGA Application Platform 3.3.

Remediation/Fixes

This vulnerability is resolved in the IBM TRIRIGA Application Platform 3.5.0.1, 3.4.2.3, and 3.3.2.6 fix packs. The IBM TRIRIGA Application Platform 3.5.0.1 and 3.4.2.3 fix packs are available on Fix Central. The 3.3.2.6 fix pack is available as a limited available fix pack, and can be requested through customer support.

For any IBM TRIRIGA Application Platform prior to 3.3.2, IBM TRIRIGA recommends upgrading to a fixed, supported IBM TRIRIGA Application platform.

Workarounds and Mitigations

Until you apply the fixes, it may be possible to reduce the risk of a successful attack by restricting access to internal networks, and not allowing external/Internet access to the application.

0.001 Low

EPSS

Percentile

43.5%

Related for 31B2B5A736EA4B57F6B75FDB5266E8388F33501613A67FFF28D286D1BBC71B2A