CVE-2016-5990
medium
CVSS v3
6.3
CVSS v2
6.5
VIR risk
6.3
Description
IBM Security Privileged Identity Manager Virtual Appliance allows an authenticated user to upload malicious files that would be automatically executed by the server.
Predictions
Exploit likelihood
73%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@us.ibm.com — http://www.securityfocus.com/bid/95199
Vendor advisory: psirt@us.ibm.com — http://www.ibm.com/support/docview.wss?uid=swg21996614
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ibm | security_privileged_identity_manager | 2.0.2 | |
| ibm | security_privileged_identity_manager | 2.1 | |
References
CWEs
CWE-284
Verify integrity in audit chain (admin only). AS-IS.