CVE-2016-9710
Status: ModifiedMedium (5.3)—
IBM Predictive Solutions Foundation (formerly PMQ) could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL to specify a file from the local system, which could allow the attacker to obtain sensitive information. IBM X-Force ID: 119618.
CVSS
- Version: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Base score: 5.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.57%
- Percentile among all scored CVEs: 74
- Score date: 10/3/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-200
References
- http://www.ibm.com/support/docview.wss?uid=swg22004036
- http://www.securityfocus.com/bid/98975
- https://exchange.xforce.ibmcloud.com/vulnerabilities/119618
- http://www.ibm.com/support/docview.wss?uid=swg22004036
- http://www.securityfocus.com/bid/98975
- https://exchange.xforce.ibmcloud.com/vulnerabilities/119618
Raw JSON (NVD)
Show
{
"id": "CVE-2016-9710",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "psirt@us.ibm.com",
"affectedData": [
{
"vendor": "IBM",
"product": "Cognos Business Intelligence",
"versions": [
{
"status": "affected",
"version": "10.1.1"
},
{
"status": "affected",
"version": "10.2"
},
{
"status": "affected",
"version": "10.2.1"
},
{
"status": "affected",
"version": "10.2.1.1"
},
{
"status": "affected",
"version": "10.2.2"
}
]
}
]
}
],
"published": "2017-06-07T17:29:00.647",
"references": [
{
"url": "http://www.ibm.com/support/docview.wss?uid=swg22004036",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "psirt@us.ibm.com"
},
{
"url": "http://www.securityfocus.com/bid/98975",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "psirt@us.ibm.com"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/119618",
"tags": [
"VDB Entry",
"Vendor Advisory"
],
"source": "psirt@us.ibm.com"
},
{
"url": "http://www.ibm.com/support/docview.wss?uid=swg22004036",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/98975",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/119618",
"tags": [
"VDB Entry",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "IBM Predictive Solutions Foundation (formerly PMQ) could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL to specify a file from the local system, which could allow the attacker to obtain sensitive information. IBM X-Force ID: 119618."
},
{
"lang": "es",
"value": "Predictive Solutions Foundation de IBM (anteriormente PMQ), podría permitir a un atacante remoto incluir archivos arbitrarios. Un atacante remoto podría enviar una URL especialmente diseñada para especificar un archivo del sistema local, lo que podría permitirle al atacante obtener información confidencial. ID de IBM X-Force: 119618."
}
],
"lastModified": "2026-06-17T00:56:27.883",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:cognos_business_intelligence_server:10.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F31E5733-732B-44C1-B046-18523A8B2B31"
},
{
"criteria": "cpe:2.3:a:ibm:cognos_business_intelligence_server:10.2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3EB66D31-26D2-4D91-ABF9-3C923730401B"
},
{
"criteria": "cpe:2.3:a:ibm:cognos_business_intelligence_server:10.2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E07C949E-36DB-4A57-B50E-E135798A9759"
},
{
"criteria": "cpe:2.3:a:ibm:cognos_business_intelligence_server:10.2.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4E44DA96-93BA-49B3-97D0-F50CCEC20D49"
},
{
"criteria": "cpe:2.3:a:ibm:cognos_business_intelligence_server:10.2.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "71B3B8BE-C8B5-44C8-BAD5-48958F2B5793"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@us.ibm.com"
}