CVE-2016-3021
low
CVSS v3
2.7
CVSS v2
4.0
VIR risk
2.7
Description
IBM Security Access Manager for Web could allow an authenticated attacker to obtain sensitive information from error message using a specially crafted HTTP request.
Predictions
Exploit likelihood
39%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@us.ibm.com — http://www.ibm.com/support/docview.wss?uid=swg21995436
References
CWEs
CWE-200
Verify integrity in audit chain (admin only). AS-IS.