Show plain JSON{"id": "CVE-2016-0246", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.3, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "CHANGED", "version": "3.0", "baseScore": 6.1, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "integrityImpact": "LOW", "userInteraction": "REQUIRED", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "LOW"}, "impactScore": 2.7, "exploitabilityScore": 2.8}]}, "published": "2016-10-22T03:59:06.487", "references": [{"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21990377", "tags": ["Patch", "Vendor Advisory"], "source": "psirt@us.ibm.com"}, {"url": "http://www.securityfocus.com/bid/93400", "source": "psirt@us.ibm.com"}, {"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21990377", "tags": ["Patch", "Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/bid/93400", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-79"}]}], "descriptions": [{"lang": "en", "value": "Cross-site scripting (XSS) vulnerability in IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote attackers to inject arbitrary web script or HTML via a crafted URL."}, {"lang": "es", "value": "Vulnerabilidad de XSS en IBM Security Guardium 8.2 en versiones anteriores a p310, 9.x hasta la versi\u00f3n 9.5 en versiones anteriores a p700 y 10.x hasta la versi\u00f3n 10.1 en versiones anteriores a p100 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a trav\u00e9s de una URL manipulada."}], "lastModified": "2025-04-12T10:46:40.837", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:ibm:security_guardium:8.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "57130C1B-80A6-4A33-8AD3-5C6F4669F3E7"}, {"criteria": "cpe:2.3:a:ibm:security_guardium:9.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "64C62744-22BD-4038-8257-822ADDAC370D"}, {"criteria": "cpe:2.3:a:ibm:security_guardium:9.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "26EA5CC2-F4BE-4F22-AC85-1956EFA88B66"}, {"criteria": "cpe:2.3:a:ibm:security_guardium:9.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "37342DD2-055B-429C-9231-2D9FE70B5AE5"}, {"criteria": "cpe:2.3:a:ibm:security_guardium:10.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "552A0A69-388F-4842-A882-78F267D4BF09"}, {"criteria": "cpe:2.3:a:ibm:security_guardium:10.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "148A8443-DF7A-42AA-8D86-128CCC1D871E"}, {"criteria": "cpe:2.3:a:ibm:security_guardium:10.01:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5C57C27B-960F-4DC9-AD76-2B71BB9D5887"}], "operator": "OR"}]}], "sourceIdentifier": "psirt@us.ibm.com"}