CVE-2016-9717
medium
CVSS v3
6.5
CVSS v2
4.0
VIR risk
6.5
Description
HTTP Parameter Override is identified in the IBM Infosphere Master Data Management (MDM) 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 product. It enables attackers by exposing the presence of duplicated parameters which may produce an anomalous behavior in the application that can be potentially exploited.
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@us.ibm.com — https://exchange.xforce.ibmcloud.com/vulnerabilities/119730
Vendor advisory: psirt@us.ibm.com — http://www.ibm.com/support/docview.wss?uid=swg22006605
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ibm | infosphere_master_data_management_server | 10.1 | |
| ibm | infosphere_master_data_management_server | 11.0 | |
| ibm | infosphere_master_data_management_server | 11.3 | |
| ibm | infosphere_master_data_management_server | 11.4 | |
| ibm | infosphere_master_data_management_server | 11.5 | |
| ibm | infosphere_master_data_management_server | 11.6 | |
References
- http://www.ibm.com/support/docview.wss?uid=swg22006605
- http://www.securityfocus.com/bid/100074
- https://exchange.xforce.ibmcloud.com/vulnerabilities/119730
- http://www.ibm.com/support/docview.wss?uid=swg22006605
- http://www.securityfocus.com/bid/100074
- https://exchange.xforce.ibmcloud.com/vulnerabilities/119730
CWEs
CWE-20
Verify integrity in audit chain (admin only). AS-IS.