CVE-2016-5979
Summary
| CVE | CVE-2016-5979 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-05-15 21:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | IBM Distributed Marketing 8.6, 9.0, and 10.0 could allow a privileged authenticated user to create an instance that gets created with security profile not valid for the templates, that results in the new instance not accessible for the intended user. IBM X-Force ID: 116379. |
Risk And Classification
Primary CVSS: v3.0 2.7 LOW from [email protected]
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
Problem Types: CWE-264 | Denial of Service
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 2.7 | LOW | CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L |
| 2.0 | [email protected] | Primary | 4 | AV:N/AC:L/Au:S/C:N/I:N/A:P |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
HighUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
LowCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:S/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Distributed Marketing | 10.0.0.0 | All | All | All |
| Application | Ibm | Distributed Marketing | 10.0.0.1 | All | All | All |
| Application | Ibm | Distributed Marketing | 8.6.0.0 | All | All | All |
| Application | Ibm | Distributed Marketing | 8.6.0.10 | All | All | All |
| Application | Ibm | Distributed Marketing | 8.6.0.2 | All | All | All |
| Application | Ibm | Distributed Marketing | 8.6.0.3 | All | All | All |
| Application | Ibm | Distributed Marketing | 8.6.0.4 | All | All | All |
| Application | Ibm | Distributed Marketing | 8.6.0.5 | All | All | All |
| Application | Ibm | Distributed Marketing | 8.6.0.6 | All | All | All |
| Application | Ibm | Distributed Marketing | 8.6.0.7 | All | All | All |
| Application | Ibm | Distributed Marketing | 8.6.0.8 | All | All | All |
| Application | Ibm | Distributed Marketing | 8.6.0.9 | All | All | All |
| Application | Ibm | Distributed Marketing | 9.1.0.0 | All | All | All |
| Application | Ibm | Distributed Marketing | 9.1.0.10 | All | All | All |
| Application | Ibm | Distributed Marketing | 9.1.0.11 | All | All | All |
| Application | Ibm | Distributed Marketing | 9.1.0.2 | All | All | All |
| Application | Ibm | Distributed Marketing | 9.1.0.3 | All | All | All |
| Application | Ibm | Distributed Marketing | 9.1.0.4 | All | All | All |
| Application | Ibm | Distributed Marketing | 9.1.0.5 | All | All | All |
| Application | Ibm | Distributed Marketing | 9.1.0.6 | All | All | All |
| Application | Ibm | Distributed Marketing | 9.1.0.7 | All | All | All |
| Application | Ibm | Distributed Marketing | 9.1.0.8 | All | All | All |
| Application | Ibm | Distributed Marketing | 9.1.0.9 | All | All | All |
| Application | Ibm | Distributed Marketing | 9.1.2.0 | All | All | All |
| Application | Ibm | Distributed Marketing | 9.1.2.1 | All | All | All |
| Application | Ibm | Distributed Marketing | 9.1.2.2 | All | All | All |
| Application | Ibm | Distributed Marketing | 9.1.2.3 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | IBM Corporation | Distributed Marketing | affected 8.6, 9.0, 9.1, 9.1.1, 9.1.2, 10.0 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.