CVE Vulnerabilities

CVE-2016-0362

Published: Jul 01, 2016 | Modified: Aug 11, 2016
CVSS 3.x
7.7
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, and trigger network traffic to arbitrary intranet or Internet hosts, via a crafted proxy request to a web service.

Affected Software

Name Vendor Start Version End Version
Tririga_application_platform Ibm 3.3.0.0 (including) 3.3.0.0 (including)
Tririga_application_platform Ibm 3.3.0.1 (including) 3.3.0.1 (including)
Tririga_application_platform Ibm 3.3.0.2 (including) 3.3.0.2 (including)
Tririga_application_platform Ibm 3.3.1.0 (including) 3.3.1.0 (including)
Tririga_application_platform Ibm 3.3.1.1 (including) 3.3.1.1 (including)
Tririga_application_platform Ibm 3.3.1.2 (including) 3.3.1.2 (including)
Tririga_application_platform Ibm 3.3.1.3 (including) 3.3.1.3 (including)
Tririga_application_platform Ibm 3.3.2.0 (including) 3.3.2.0 (including)
Tririga_application_platform Ibm 3.3.2.1 (including) 3.3.2.1 (including)
Tririga_application_platform Ibm 3.3.2.2 (including) 3.3.2.2 (including)
Tririga_application_platform Ibm 3.3.2.3 (including) 3.3.2.3 (including)
Tririga_application_platform Ibm 3.3.2.4 (including) 3.3.2.4 (including)
Tririga_application_platform Ibm 3.3.2.5 (including) 3.3.2.5 (including)
Tririga_application_platform Ibm 3.4.0.0 (including) 3.4.0.0 (including)
Tririga_application_platform Ibm 3.4.0.1 (including) 3.4.0.1 (including)
Tririga_application_platform Ibm 3.4.1.0 (including) 3.4.1.0 (including)
Tririga_application_platform Ibm 3.4.1.1 (including) 3.4.1.1 (including)
Tririga_application_platform Ibm 3.4.1.2 (including) 3.4.1.2 (including)
Tririga_application_platform Ibm 3.4.1.3 (including) 3.4.1.3 (including)
Tririga_application_platform Ibm 3.4.2.0 (including) 3.4.2.0 (including)
Tririga_application_platform Ibm 3.4.2.1 (including) 3.4.2.1 (including)
Tririga_application_platform Ibm 3.4.2.2 (including) 3.4.2.2 (including)
Tririga_application_platform Ibm 3.4.2.3 (including) 3.4.2.3 (including)
Tririga_application_platform Ibm 3.5.0.0 (including) 3.5.0.0 (including)
Tririga_application_platform Ibm 3.5.0.1 (including) 3.5.0.1 (including)

References