« Volver al listado

CVE-2016-2961

Estado: ModificadaMedia (5.3)—

The integration server in IBM Integration Bus 9 before 9.0.0.6 and 10 before 10.0.0.5 and WebSphere Message Broker 8 before 8.0.0.8 allows remote attackers to obtain sensitive Tomcat version information by sending a malformed POST request and then reading the Java stack trace.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2016-2961",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@us.ibm.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2016-07-02T14:59:17.383",
  "references": [
    {
      "url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IT15188",
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "http://www-01.ibm.com/support/docview.wss?uid=swg21985017",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IT15188",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www-01.ibm.com/support/docview.wss?uid=swg21985017",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The integration server in IBM Integration Bus 9 before 9.0.0.6 and 10 before 10.0.0.5 and WebSphere Message Broker 8 before 8.0.0.8 allows remote attackers to obtain sensitive Tomcat version information by sending a malformed POST request and then reading the Java stack trace."
    },
    {
      "lang": "es",
      "value": "El servidor de integración en IBM Integration Bus 9 en versiones anteriores a 9.0.0.6 y 10 en versiones anteriores a 10.0.0.5 y WebSphere Message Broker 8 en versiones anteriores a 8.0.0.8 permite a atacantes remotos obtener información sensible de versión Tomcat enviando una petición de POST mal formada y, después, leyendo el rastro en pila de Java."
    }
  ],
  "lastModified": "2026-06-17T00:44:44.250",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ibm:integration_bus:9.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4D9B868C-9348-4D31-95F9-FEC3D91158AE"
            },
            {
              "criteria": "cpe:2.3:a:ibm:integration_bus:9.0.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "725E3F95-4096-497D-8F2A-02C185ACF8CB"
            },
            {
              "criteria": "cpe:2.3:a:ibm:integration_bus:9.0.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ACB80DEF-E09A-4B51-96B8-75F0AD9C6499"
            },
            {
              "criteria": "cpe:2.3:a:ibm:integration_bus:9.0.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "576FE339-BD08-4994-B31A-15BC521650E7"
            },
            {
              "criteria": "cpe:2.3:a:ibm:integration_bus:9.0.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "371E03D4-BDD9-40A8-B24B-43C320C9F3E5"
            },
            {
              "criteria": "cpe:2.3:a:ibm:integration_bus:9.0.0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C319D81D-E66B-47E6-A731-D5074314B94B"
            },
            {
              "criteria": "cpe:2.3:a:ibm:integration_bus:10.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "92E6A5C9-29C2-458D-AA67-E74945E2012F"
            },
            {
              "criteria": "cpe:2.3:a:ibm:integration_bus:10.0.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6309A833-9490-494A-BE3A-BA79133BD6E7"
            },
            {
              "criteria": "cpe:2.3:a:ibm:integration_bus:10.0.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "50810A19-BEDC-4DF6-BA82-DAA1F96D5400"
            },
            {
              "criteria": "cpe:2.3:a:ibm:integration_bus:10.0.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "97486673-4740-4F4F-8956-73C06B477096"
            },
            {
              "criteria": "cpe:2.3:a:ibm:integration_bus:10.0.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "79E917E9-DE5E-482A-9A20-823DF475BE66"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ibm:websphere_message_broker:8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0F93BF57-FD4F-456C-8DFD-CEF8B5AEF35D"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_message_broker:8.0.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B859DAA9-1B0E-47CE-813D-108776C3B239"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_message_broker:8.0.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2458C42A-90F7-457C-AAD6-205D9893A993"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_message_broker:8.0.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8BFEC988-5E94-474F-9A60-966B8FA8B8F6"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_message_broker:8.0.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BE5CCF85-8149-43DB-A594-99895D94F447"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_message_broker:8.0.0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EA0D7E80-2607-4567-8D1C-2ADA32F174D8"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_message_broker:8.0.0.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "32E57C58-4A30-43BE-B8CC-E6B38E67AA8C"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_message_broker:8.0.0.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D2C048F0-D615-49E6-9B50-22E259C02C5B"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@us.ibm.com"
}