Vulnerability Description
The notifications component in IBM TRIRIGA Applications 10.4 and 10.5 before 10.5.1 allows remote authenticated users to obtain sensitive password information, and consequently gain privileges, via unspecified vectors.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Tririga Application Platform | 10.4 |
Related Weaknesses (CWE)
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV84740Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21984304MitigationVendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV84740Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21984304MitigationVendor Advisory
FAQ
What is CVE-2016-2917?
CVE-2016-2917 is a vulnerability with a CVSS score of 8.8 (HIGH). The notifications component in IBM TRIRIGA Applications 10.4 and 10.5 before 10.5.1 allows remote authenticated users to obtain sensitive password information, and consequently gain privileges, via un...
How severe is CVE-2016-2917?
CVE-2016-2917 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-2917?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Tririga Application Platform.