CVE-2016-8982
Summary
| CVE | CVE-2016-8982 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-02-01 22:59:01 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | IBM InfoSphere Information Server stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. |
Risk And Classification
Primary CVSS: v3.0 5.3 MEDIUM from [email protected]
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Problem Types: CWE-200 | Obtain Information
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 5.3 | MEDIUM | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
| 2.0 | [email protected] | Primary | 5 | AV:N/AC:L/Au:N/C:P/I:N/A:N |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
LowIntegrity
NoneAvailability
NoneCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Infosphere Datastage | 11.3 | All | All | All |
| Application | Ibm | Infosphere Datastage | 8.7 | All | All | All |
| Application | Ibm | Infosphere Datastage | 9.1 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | IBM Corporation | InfoSphere DataStage | affected 8.5 | Not specified |
| CNA | IBM Corporation | InfoSphere DataStage | affected 9.1 | Not specified |
| CNA | IBM Corporation | InfoSphere DataStage | affected 11.3 | Not specified |
| CNA | IBM Corporation | InfoSphere DataStage | affected 8.7 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM Security Bulletin: IBM InfoSphere DataStage exposes sensitive information during certain operations (CVE-2016-8982) - United States | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | Patch, Vendor Advisory |
| IBM InfoSphere DataStage URL Parameter Usage Lets Remote or Local Users Obtain Potentially Sensitive Information on the Target System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| IBM InfoSphere DataStage CVE-2016-8982 Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.