Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-3043


IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.


Published

2017-02-01T20:59:00.770

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 5.9 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System ibm security_access_manager_for_web_7.0_firmware * Yes
Hardware ibm security_access_manager_for_web_appliance 7.0 No
Operating System ibm security_access_manager_for_web_8.0_firmware * Yes
Hardware ibm security_access_manager_for_web_appliance 8.0 No
Application ibm security_access_manager_for_mobile * Yes
Hardware ibm security_access_manager_for_mobile_appliance 8.0 No
Operating System ibm security_access_manager_9.0_firmware * Yes

References