{"api_version":"1","generated_at":"2026-07-23T22:40:38+00:00","cve":"CVE-2016-0342","urls":{"html":"https://cve.report/CVE-2016-0342","api":"https://cve.report/api/cve/CVE-2016-0342.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-0342","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-0342"},"summary":{"title":"CVE-2016-0342","description":"IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to read or modify arbitrary reports by leveraging an incorrect grant of access. IBM X-Force ID: 111783.","state":"PUBLIC","assigner":"psirt@us.ibm.com","published_at":"2018-02-02 21:29:00","updated_at":"2018-02-15 18:12:00"},"problem_types":["CWE-284"],"metrics":[],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/111783","name":"ibm-tririga-cve20160342-info-disc(111783)","refsource":"XF","tags":["VDB Entry","Vendor Advisory"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21980252","name":"http://www-01.ibm.com/support/docview.wss?uid=swg21980252","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Security Bulletin: IBM TRIRIGA Application Platform Privilege Escalation (CVE-2016-0342)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-0342","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-0342","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"342","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"tririga_application_platform","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"342","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"tririga_application_platform","cpe6":"3.5.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"342","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"tririga_application_platform","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"342","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"tririga_application_platform","cpe6":"3.5.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"psirt@us.ibm.com","ID":"CVE-2016-0342","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to read or modify arbitrary reports by leveraging an incorrect grant of access. IBM X-Force ID: 111783."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www-01.ibm.com/support/docview.wss?uid=swg21980252","refsource":"CONFIRM","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21980252"},{"name":"ibm-tririga-cve20160342-info-disc(111783)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/111783"}]}},"nvd":{"publishedDate":"2018-02-02 21:29:00","lastModifiedDate":"2018-02-15 18:12:00","problem_types":["CWE-284"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.5},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":5.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":4.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:tririga_application_platform:3.5.0.0:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:tririga_application_platform:*:*:*:*:*:*:*:*","versionStartIncluding":"3.3.0.0","versionEndExcluding":"3.3.2.6","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:tririga_application_platform:*:*:*:*:*:*:*:*","versionStartIncluding":"3.4.0.0","versionEndExcluding":"3.4.2.3","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"342","Ordinal":"85898","Title":"CVE-2016-0342","CVE":"CVE-2016-0342","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"342","Ordinal":"1","NoteData":"IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to read or modify arbitrary reports by leveraging an incorrect grant of access. IBM X-Force ID: 111783.","Type":"Description","Title":null},{"CveYear":"2016","CveId":"342","Ordinal":"2","NoteData":"2018-02-02","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"342","Ordinal":"3","NoteData":"2018-02-02","Type":"Other","Title":"Modified"}]}}}