ZeroHour

CVE-2016-2945

CVSS 3.0
7.5 high
EPSS
2%p78
Published
()
Modified
Description

The API Discovery implementation in IBM WebSphere Application Server (WAS) 8.5.5.8 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 allows remote authenticated users to gain privileges via an external reference in a Swagger document.

Vendors
ibm
Products
websphere application server
Weakness
CWE-264
Vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.