Show plain JSON{"id": "CVE-2016-3045", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.3, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 3.7, "attackVector": "NETWORK", "baseSeverity": "LOW", "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "HIGH", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "LOW"}, "impactScore": 1.4, "exploitabilityScore": 2.2}]}, "published": "2017-02-01T20:59:00.817", "references": [{"url": "http://www.ibm.com/support/docview.wss?uid=swg21995435", "tags": ["Patch", "Vendor Advisory"], "source": "psirt@us.ibm.com"}, {"url": "http://www.securityfocus.com/bid/95103", "tags": ["Third Party Advisory", "VDB Entry"], "source": "psirt@us.ibm.com"}, {"url": "http://www.ibm.com/support/docview.wss?uid=swg21995435", "tags": ["Patch", "Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/bid/95103", "tags": ["Third Party Advisory", "VDB Entry"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-200"}]}], "descriptions": [{"lang": "en", "value": "IBM Security Access Manager for Web stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referer header or browser history."}, {"lang": "es", "value": "IBM Security Access Manager para Web almacena informaci\u00f3n sensible en par\u00e1metros URL. Esto puede dar lugar a la divulgaci\u00f3n de informaci\u00f3n si las partes no autorizadas tienen acceso a las URL a trav\u00e9s de los registros del servidor, el encabezado referente o el historial del navegador."}], "lastModified": "2025-04-20T01:37:25.860", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:ibm:security_access_manager:9.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F49FA0E2-5FEB-4831-980E-CFBE7E44277A"}, {"criteria": "cpe:2.3:a:ibm:security_access_manager:9.0.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A6B67748-2677-44E7-B43D-857EBCA926C2"}, {"criteria": "cpe:2.3:a:ibm:security_access_manager:9.0.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2AEE420D-4686-4C58-B77A-2E509983F4C3"}, {"criteria": "cpe:2.3:a:ibm:security_access_manager_for_mobile:8.0.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "44310E32-EA05-420B-8676-4E6EEAFB6631"}, {"criteria": "cpe:2.3:a:ibm:security_access_manager_for_mobile:8.0.0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2EE90667-0C16-4E4B-98DC-A6AD7A073D64"}, {"criteria": "cpe:2.3:a:ibm:security_access_manager_for_mobile:8.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AA8844A0-17D5-4EE9-85C4-518DACE7C9D0"}, {"criteria": "cpe:2.3:a:ibm:security_access_manager_for_mobile:8.0.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F0D646B2-7308-43A0-AE76-873946FB024E"}, {"criteria": "cpe:2.3:a:ibm:security_access_manager_for_mobile:8.0.1.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4B1988E5-DFE6-4282-B9D3-6655297B481B"}, {"criteria": "cpe:2.3:a:ibm:security_access_manager_for_mobile:8.0.1.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4BEF4063-73D7-416D-AD21-CDC1C0534677"}, {"criteria": "cpe:2.3:a:ibm:security_access_manager_for_web:7.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "58D7CF23-E40B-48FE-B1F2-BAD47500A98B"}, {"criteria": "cpe:2.3:a:ibm:security_access_manager_for_web:8.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F6658BD1-B9F9-4C68-AC7B-66E0630ACD68"}, {"criteria": "cpe:2.3:a:ibm:security_access_manager_for_web:8.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5000C473-1151-4C1C-BCB8-C410D8BDA362"}, {"criteria": "cpe:2.3:a:ibm:security_access_manager_for_web:8.0.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AB037932-234B-41AD-8119-D964796ADDFD"}, {"criteria": "cpe:2.3:a:ibm:security_access_manager_for_web:8.0.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8BA1DA71-91C8-4989-98B9-E924ED7B272A"}, {"criteria": "cpe:2.3:a:ibm:security_access_manager_for_web:8.0.1.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3F884817-A712-4A89-B199-2E2483CD8363"}, {"criteria": "cpe:2.3:a:ibm:security_access_manager_for_web:8.0.1.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "52F627D1-6FB4-47A2-817D-F9EC914DAC51"}], "operator": "OR"}]}], "sourceIdentifier": "psirt@us.ibm.com"}