{ "id": "CVE-2016-5959", "sourceIdentifier": "psirt@us.ibm.com", "published": "2017-06-07T17:29:00.427", "lastModified": "2017-06-13T16:37:54.747", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 116136." }, { "lang": "es", "value": "IBM Security Privileged Identity Manager versi\u00f3n 2.0.2 y 2.1.0 almacena informaci\u00f3n confidencial en par\u00e1metros de URL. Esto puede provocar una divulgaci\u00f3n de informaci\u00f3n si partes no autorizadas tienen acceso a las URL a trav\u00e9s de los registros del servidor, los encabezados de las peticiones, o el historial del navegador. IBM X-Force ID: 116136" } ], "metrics": { "cvssMetricV30": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseScore": 5.3, "baseSeverity": "MEDIUM" }, "exploitabilityScore": 3.9, "impactScore": 1.4 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N", "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseScore": 5.0 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 10.0, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-200" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:security_privileged_identity_manager:2.0.2:*:*:*:*:*:*:*", "matchCriteriaId": "D07547A7-E87E-4085-983F-29BD485E3160" }, { "vulnerable": true, "criteria": "cpe:2.3:a:ibm:security_privileged_identity_manager:2.1:*:*:*:*:*:*:*", "matchCriteriaId": "8C26B4C2-D6EC-4367-9D59-BE9FF8DC2395" } ] } ] } ], "references": [ { "url": "http://www.ibm.com/support/docview.wss?uid=swg22003092", "source": "psirt@us.ibm.com", "tags": [ "Patch", "Vendor Advisory" ] }, { "url": "http://www.securityfocus.com/bid/98829", "source": "psirt@us.ibm.com", "tags": [ "Third Party Advisory", "VDB Entry" ] }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/116136", "source": "psirt@us.ibm.com", "tags": [ "VDB Entry", "Vendor Advisory" ] } ] }