CVE-2016-2917

HIGH

IBM TRIRIGA Application Platform 10.4-10.5 - Authenticated Sensitive Password Information Disclosure

Title source: llm
STIX 2.1

Description

The notifications component in IBM TRIRIGA Applications 10.4 and 10.5 before 10.5.1 allows remote authenticated users to obtain sensitive password information, and consequently gain privileges, via unspecified vectors.

References (2)

Core 2
Core References
Mitigation, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21984304
Vendor Advisory vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IV84740

Scores

CVSS v3 8.8
EPSS 0.0125
EPSS Percentile 66.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-264
Status published
Products (2)
ibm/tririga_application_platform 10.4
ibm/tririga_application_platform 10.5
Published Nov 30, 2016
Tracked Since Feb 18, 2026