Thursday, December 15, 2016

IBM Security Bulletin: IBM Security Access Manager appliances are affected by an information disclosure vulnerability (CVE-2016-3045)

IBM Security Access Manager appliances store sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referer header or browser history.

CVE(s): CVE-2016-3045

Affected product(s) and affected version(s):

IBM Security Access Manager for Web 7.0 appliances, all firmware versions.

IBM Security Access Manager for Web 8.0 appliances, all firmware versions.

IBM Security Access Manager for Mobile 8.0 appliances, all firmware versions.

IBM Security Access Manager 9.0 appliances, all firmware versions.

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2hxIl3m
X-Force Database: http://ift.tt/2hAxP8G



from IBM Product Security Incident Response Team http://ift.tt/2hxG2gU

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.