CVE-2016-9717
Summary
| CVE | CVE-2016-9717 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-07-31 21:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | HTTP Parameter Override is identified in the IBM Infosphere Master Data Management (MDM) 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 product. It enables attackers by exposing the presence of duplicated parameters which may produce an anomalous behavior in the application that can be potentially exploited. |
Risk And Classification
Primary CVSS: v3.0 6.5 MEDIUM from [email protected]
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Problem Types: CWE-20 | Gain Access
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 6.5 | MEDIUM | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
| 2.0 | [email protected] | Primary | 4 | AV:N/AC:L/Au:S/C:N/I:P/A:N |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
HighAvailability
NoneCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:S/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Infosphere Master Data Management Server | 10.1 | All | All | All |
| Application | Ibm | Infosphere Master Data Management Server | 11.0 | All | All | All |
| Application | Ibm | Infosphere Master Data Management Server | 11.3 | All | All | All |
| Application | Ibm | Infosphere Master Data Management Server | 11.4 | All | All | All |
| Application | Ibm | Infosphere Master Data Management Server | 11.5 | All | All | All |
| Application | Ibm | Infosphere Master Data Management Server | 11.6 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | IBM | InfoSphere Master Data Management | affected 10.1 | Not specified |
| CNA | IBM | InfoSphere Master Data Management | affected 11.0 | Not specified |
| CNA | IBM | InfoSphere Master Data Management | affected 11.3 | Not specified |
| CNA | IBM | InfoSphere Master Data Management | affected 11.4 | Not specified |
| CNA | IBM | InfoSphere Master Data Management | affected 10.1.0 | Not specified |
| CNA | IBM | InfoSphere Master Data Management | affected 11.0.0 | Not specified |
| CNA | IBM | InfoSphere Master Data Management | affected 11.5 | Not specified |
| CNA | IBM | InfoSphere Master Data Management | affected 11.6 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM InfoSphere Master Data Management CVE-2016-9717 Security Bypass Vulnerablity | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Security Bulletin: IBM InfoSphere Master Data Management Server is vulnerable to HTTP Parameter Override discovered in MDM User Interface (CVE-2016-9717) | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | Patch, Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | VDB Entry, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.