{"api_version":"1","generated_at":"2026-07-23T08:32:16+00:00","cve":"CVE-2016-8982","urls":{"html":"https://cve.report/CVE-2016-8982","api":"https://cve.report/api/cve/CVE-2016-8982.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-8982","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-8982"},"summary":{"title":"CVE-2016-8982","description":"IBM InfoSphere Information Server stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.","state":"PUBLISHED","assigner":"ibm","published_at":"2017-02-01 22:59:01","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-200","Obtain Information"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.ibm.com/support/docview.wss?uid=swg21995895","name":"http://www.ibm.com/support/docview.wss?uid=swg21995895","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"IBM Security Bulletin: IBM InfoSphere DataStage exposes sensitive information during certain operations (CVE-2016-8982) - United States","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1037616","name":"http://www.securitytracker.com/id/1037616","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM InfoSphere DataStage URL Parameter Usage Lets Remote or Local Users Obtain Potentially Sensitive Information on the Target System - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/95651","name":"http://www.securityfocus.com/bid/95651","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM InfoSphere DataStage CVE-2016-8982 Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-8982","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-8982","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"IBM Corporation","product":"InfoSphere DataStage","version":"affected 8.5","platforms":[]},{"source":"CNA","vendor":"IBM Corporation","product":"InfoSphere DataStage","version":"affected 9.1","platforms":[]},{"source":"CNA","vendor":"IBM Corporation","product":"InfoSphere DataStage","version":"affected 11.3","platforms":[]},{"source":"CNA","vendor":"IBM Corporation","product":"InfoSphere DataStage","version":"affected 8.7","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"8982","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"infosphere_datastage","cpe6":"11.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"8982","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"infosphere_datastage","cpe6":"8.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"8982","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"infosphere_datastage","cpe6":"9.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T02:35:02.563Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.ibm.com/support/docview.wss?uid=swg21995895"},{"name":"95651","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/95651"},{"name":"1037616","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1037616"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"InfoSphere DataStage","vendor":"IBM Corporation","versions":[{"status":"affected","version":"8.5"},{"status":"affected","version":"9.1"},{"status":"affected","version":"11.3"},{"status":"affected","version":"8.7"}]}],"datePublic":"2017-01-13T00:00:00.000Z","descriptions":[{"lang":"en","value":"IBM InfoSphere Information Server stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history."}],"problemTypes":[{"descriptions":[{"description":"Obtain Information","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-25T09:57:01.000Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.ibm.com/support/docview.wss?uid=swg21995895"},{"name":"95651","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/95651"},{"name":"1037616","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1037616"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@us.ibm.com","ID":"CVE-2016-8982","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"InfoSphere DataStage","version":{"version_data":[{"version_value":"8.5"},{"version_value":"9.1"},{"version_value":"11.3"},{"version_value":"8.7"}]}}]},"vendor_name":"IBM Corporation"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"IBM InfoSphere Information Server stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Obtain Information"}]}]},"references":{"reference_data":[{"name":"http://www.ibm.com/support/docview.wss?uid=swg21995895","refsource":"CONFIRM","url":"http://www.ibm.com/support/docview.wss?uid=swg21995895"},{"name":"95651","refsource":"BID","url":"http://www.securityfocus.com/bid/95651"},{"name":"1037616","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1037616"}]}}}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2016-8982","datePublished":"2017-02-01T22:00:00.000Z","dateReserved":"2016-10-25T00:00:00.000Z","dateUpdated":"2024-08-06T02:35:02.563Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-02-01 22:59:01","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-200","Obtain Information"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:infosphere_datastage:8.7:*:*:*:*:*:*:*","matchCriteriaId":"2CB1760D-FED4-4430-9CFB-83608956E424"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:infosphere_datastage:9.1:*:*:*:*:*:*:*","matchCriteriaId":"6EADE407-3A84-49ED-B818-63B42EE47EBA"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:infosphere_datastage:11.3:*:*:*:*:*:*:*","matchCriteriaId":"BEE407E4-910C-4AF1-B87B-F9B01759DDFC"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"8982","Ordinal":"1","Title":"CVE-2016-8982","CVE":"CVE-2016-8982","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"8982","Ordinal":"1","NoteData":"IBM InfoSphere Information Server stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.","Type":"Description","Title":"CVE-2016-8982"},{"CveYear":"2016","CveId":"8982","Ordinal":"2","NoteData":"2017-02-01","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"8982","Ordinal":"3","NoteData":"2017-07-25","Type":"Other","Title":"Modified"}]}}}