CVE Vulnerabilities

CVE-2016-2945

Published: Jul 08, 2016 | Modified: Nov 28, 2016
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The API Discovery implementation in IBM WebSphere Application Server (WAS) 8.5.5.8 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 allows remote authenticated users to gain privileges via an external reference in a Swagger document.

Affected Software

Name Vendor Start Version End Version
Websphere_application_server Ibm 8.5.5.8 (including) 8.5.5.8 (including)
Websphere_application_server Ibm 8.5.5.9 (including) 8.5.5.9 (including)

References