Vulnerability Description
IBM Security Access Manager for Web stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referer header or browser history.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Security Access Manager | 9.0.0 |
| Ibm | Security Access Manager For Mobile | 8.0.0.0 |
| Ibm | Security Access Manager For Web | 7.0.0 |
Related Weaknesses (CWE)
References
- http://www.ibm.com/support/docview.wss?uid=swg21995435PatchVendor Advisory
- http://www.securityfocus.com/bid/95103Third Party AdvisoryVDB Entry
- http://www.ibm.com/support/docview.wss?uid=swg21995435PatchVendor Advisory
- http://www.securityfocus.com/bid/95103Third Party AdvisoryVDB Entry
FAQ
What is CVE-2016-3045?
CVE-2016-3045 is a vulnerability with a CVSS score of 3.7 (LOW). IBM Security Access Manager for Web stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referer hea...
How severe is CVE-2016-3045?
CVE-2016-3045 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-3045?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Security Access Manager, Ibm Security Access Manager For Mobile, Ibm Security Access Manager For Web.