CVE-2016-5919

HIGH

IBM Security Access Manager for Web <9.0.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM Reference #: 1996868.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1037855
Patch, Vendor Advisory x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=swg21996868

Scores

CVSS v3 7.5
EPSS 0.0013
EPSS Percentile 31.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-326
Status published
Products (21)
ibm/security_access_manager_9.0_firmware
ibm/security_access_manager_for_mobile
ibm/security_access_manager_for_web_7.0_firmware
ibm/security_access_manager_for_web_8.0_firmware
IBM Corporation/Access Manager 7.0.0
IBM Corporation/Access Manager 8.0.0
IBM Corporation/Access Manager 8.0.0.1
IBM Corporation/Access Manager 8.0.0.2
IBM Corporation/Access Manager 8.0.0.3
IBM Corporation/Access Manager 8.0.0.4
... and 11 more
Published Feb 16, 2017
Tracked Since Feb 18, 2026