6.5
CVSSv3

CVE-2016-0323

Published: 17/05/2016 Updated: 19/05/2016
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

The Auto-Scaling agent in Liberty for Java in IBM Bluemix prior to 2.7-20160321-1358 allows remote authenticated users to disable X.509 certificate validation, and consequently bypass an intended HTTPS trust-management feature, via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm bluemix -