6.5
CVSSv3

CVE-2016-3027

Published: 01/02/2017 Updated: 27/10/2020
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 5.2 | Exploitability Score: 1.2
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:P

Vulnerability Summary

IBM Security Access Manager for Web is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ibm security access manager 9.0 firmware 9.0.0

ibm security access manager 9.0 firmware 9.0.0.1

ibm security access manager 9.0 firmware 9.0.1.0

ibm security access manager for mobile 8.0 firmware 8.0.0.1

ibm security access manager for mobile 8.0 firmware 8.0.0.2

ibm security access manager for mobile 8.0 firmware 8.0.0.3

ibm security access manager for mobile 8.0 firmware 8.0.0.5

ibm security access manager for mobile 8.0 firmware 8.0.1.0

ibm security access manager for mobile 8.0 firmware 8.0.1.2

ibm security access manager for mobile 8.0 firmware 8.0.1.3

ibm security access manager for mobile 8.0 firmware 8.0.1.4

ibm security access manager for web 8.0 firmware 8.0.0.1

ibm security access manager for web 8.0 firmware 8.0.0.2

ibm security access manager for web 8.0 firmware 8.0.0.3

ibm security access manager for web 8.0 firmware 8.0.0.5

ibm security access manager for web 8.0 firmware 8.0.1.0

ibm security access manager for web 8.0 firmware 8.0.1.2

ibm security access manager for web 8.0 firmware 8.0.1.3

ibm security access manager for web 8.0 firmware 8.0.1.4