PT-2016-6740 · Ibm · Ibm Security Privileged Identity Manager Virtual Appliance
Published
2016-09-26
·
Updated
2016-11-28
·
CVE-2016-5972
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance versions 2.0.0 through 2.0.2 before FP8
Description
The issue allows remote authenticated users to obtain sensitive information or modify data. This is due to weak permissions for unspecified resources.
Recommendations
For versions 2.0.0 through 2.0.2 before FP8, update to at least 2.0.2 FP8 to resolve the issue.
Fix
Improper Access Control
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Security Privileged Identity Manager Virtual Appliance