« Volver al listado

CVE-2016-8911

Estado: ModificadaMedia (5.4)—

IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2016-8911",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@us.ibm.com",
      "affectedData": [
        {
          "vendor": "IBM Corporation",
          "product": "Kenexa LMS on Cloud",
          "versions": [
            {
              "status": "affected",
              "version": "13.0"
            },
            {
              "status": "affected",
              "version": "13.1"
            },
            {
              "status": "affected",
              "version": "13.2"
            },
            {
              "status": "affected",
              "version": "13.2.2"
            },
            {
              "status": "affected",
              "version": "13.2.3"
            },
            {
              "status": "affected",
              "version": "13.2.4"
            },
            {
              "status": "affected",
              "version": "14.0.0"
            },
            {
              "status": "affected",
              "version": "14.1.0"
            },
            {
              "status": "affected",
              "version": "14.2.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-02-01T20:59:02.630",
  "references": [
    {
      "url": "http://www.ibm.com/support/docview.wss?uid=swg21993982",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/94325",
      "tags": [
        "Technical Description",
        "VDB Entry"
      ],
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "http://www.ibm.com/support/docview.wss?uid=swg21993982",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/94325",
      "tags": [
        "Technical Description",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-254"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim."
    },
    {
      "lang": "es",
      "value": "IBM Kenexa LMS en Cloud 13.1 y 13.2 - 13.2.4 podría permitir a un atacante remoto secuestrar la acción de clic de la víctima. Al persuadir a una víctima a visitar un sitio Web malicioso, un atacante remoto podría explotar esta vulnerabilidad para secuestra las acciones de clic de la víctima y posiblemente lanzar además ataques contra la víctima."
    }
  ],
  "lastModified": "2026-06-17T00:55:10.013",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ibm:kenexa_lms_on_cloud:13.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E30D036D-554E-4E26-B12B-50835DBD5B9D"
            },
            {
              "criteria": "cpe:2.3:a:ibm:kenexa_lms_on_cloud:13.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "29B8559A-C8F7-4B9E-9ADA-A01574323D59"
            },
            {
              "criteria": "cpe:2.3:a:ibm:kenexa_lms_on_cloud:13.2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "12ABCC49-7AE3-42D4-A420-98E2CF83B853"
            },
            {
              "criteria": "cpe:2.3:a:ibm:kenexa_lms_on_cloud:13.2.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7C18D65C-E826-4579-9118-948E5F804C4F"
            },
            {
              "criteria": "cpe:2.3:a:ibm:kenexa_lms_on_cloud:13.2.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "21EF7E0D-86CB-4BAE-817B-1CA906B1F682"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@us.ibm.com"
}