PT-2017-8299 · Ibm · Ibm Security Access Manager For Web

Publicado

2017-02-07

·

Atualizado

2020-10-27

·

CVE-2016-3020

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM Security Access Manager for Web versions 7.0.0 through 9.0.0
Description The issue is caused by improper content validation, allowing a remote attacker to bypass security restrictions. An attacker could exploit this by persuading a victim to open specially-crafted content, which could then load a page with malicious content.
Recommendations For versions 7.0.0 through 9.0.0, update the content validation mechanism to properly check and restrict malicious content.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-3020

Produtos afetados

Ibm Security Access Manager For Web