CVE-2016-2917
high
CVSS v3
8.8
CVSS v2
6.5
VIR risk
8.8
Description
The notifications component in IBM TRIRIGA Applications 10.4 and 10.5 before 10.5.1 allows remote authenticated users to obtain sensitive password information, and consequently gain privileges, via unspecified vectors.
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21984304
Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg1IV84740
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ibm | tririga_application_platform | 10.4 | |
| ibm | tririga_application_platform | 10.5 | |
References
CWEs
CWE-264
Verify integrity in audit chain (admin only). AS-IS.