Lucene search

K
ibmIBM5168096D805F69A161EC6ECF487A5774909E853A50E0F5C21F4B97E1ECDF6CA6
HistoryJun 16, 2018 - 9:48 p.m.

Security Bulletin: IBM Security Access Manager appliances are affected by an information exposure vulnerability (CVE-2016-3023)

2018-06-1621:48:35
www.ibm.com
9

EPSS

0.001

Percentile

38.7%

Summary

IBM Security Access Manager appliances could allow an unauthenticated user to gain access to sensitive information by entering invalid file names.

Vulnerability Details

CVEID: CVE-2016-3023**
DESCRIPTION:** IBM Security Access Manager for Web could allow an unauthenticated user to gain access to sensitive information by entering invalid file names.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/114471 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

IBM Security Access Manager for Web 7.0 appliances, all firmware versions.

IBM Security Access Manager for Web 8.0 appliances, all firmware versions.

IBM Security Access Manager for Mobile 8.0 appliances, all firmware versions.

IBM Security Access Manager 9.0 appliances, all firmware versions.

Remediation/Fixes

IBM has provided patches for all affected versions. Follow the installation instructions in the README files included with the patch.

Product VRMF APAR Remediation
IBM Security Access Manager for Web 7.0 (appliance) IV90716 Apply Interim Fix 28:
7.0.0-ISS-WGA-IF0028
IBM Security Access Manager for Web 8.0.0.0 -
8.0.1.4 IV90677 Upgrade to 8.0.1.5:
8.0.1-ISS-WGA-FP0005
IBM Security Access Manager for Mobile 8.0.0.0 -
8.0.1.4 IV90701 Upgrade to 8.0.1.5:
8.0.1-ISS-ISAM-FP0005
IBM Security Access Manager 9.0 - 9.0.1.0 IV90496 Upgrade to 9.0.2.0:
IBM Security Access Manager V9.0.2 Multiplatform, Multilingual (CRW4EML)

Workarounds and Mitigations

None.

EPSS

0.001

Percentile

38.7%

Related for 5168096D805F69A161EC6ECF487A5774909E853A50E0F5C21F4B97E1ECDF6CA6