Vulnerability Description
IBM API Connect (aka APIConnect) before 5.0.3.0 with NPM before 2.2.8 includes certain internal server credentials in the software package, which might allow remote attackers to bypass intended access restrictions by leveraging knowledge of these credentials.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Api Connect | <= 5.0.2.0 |
| Ibm | Network Path Manager | <= 2.1.1.9 |
Related Weaknesses (CWE)
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21988212Vendor Advisory
- http://www.securityfocus.com/bid/92417Third Party AdvisoryVDB Entry
- http://www-01.ibm.com/support/docview.wss?uid=swg21988212Vendor Advisory
- http://www.securityfocus.com/bid/92417Third Party AdvisoryVDB Entry
FAQ
What is CVE-2016-3012?
CVE-2016-3012 is a vulnerability with a CVSS score of 7.5 (HIGH). IBM API Connect (aka APIConnect) before 5.0.3.0 with NPM before 2.2.8 includes certain internal server credentials in the software package, which might allow remote attackers to bypass intended access...
How severe is CVE-2016-3012?
CVE-2016-3012 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-3012?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Api Connect, Ibm Network Path Manager.