CVE-2016-0300
Summary
| CVE | CVE-2016-0300 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-02-02 21:29:00 UTC |
| Updated | 2018-02-14 15:24:00 UTC |
| Description | IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 might allow remote attackers to access arbitrary JSP pages via vectors related to improper input validation. IBM X-Force ID: 111412. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Tririga Application Platform | 3.3.0.0 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.3.0.1 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.3.0.2 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.3.1.0 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.3.1.1 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.3.1.2 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.3.1.3 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.3.2.0 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.3.2.1 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.3.2.3 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.3.2.4 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.3.2.5 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.4.0.0 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.4.1.1 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.4.1.2 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.4.1.3 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.4.2.0 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.4.2.1 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.4.2.2 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.5.0.0 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.3.0.0 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.3.0.1 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.3.0.2 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.3.1.0 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.3.1.1 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.3.1.2 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.3.1.3 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.3.2.0 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.3.2.1 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.3.2.3 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.3.2.4 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.3.2.5 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.4.0.0 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.4.1.1 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.4.1.2 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.4.1.3 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.4.2.0 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.4.2.1 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.4.2.2 | All | All | All |
| Application | Ibm | Tririga Application Platform | 3.5.0.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | VDB Entry, Vendor Advisory |
| Security Bulletin: Improper Input Validation in IBM TRIRIGA Application Platform (CVE-2016-0300) | CONFIRM | www-01.ibm.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.