SB2016071113 - Spoofing attack in IBM Security Identity Manager Virtual Appliance
Published: July 11, 2016 Updated: November 22, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Spoofing attack (CVE-ID: CVE-2016-0339)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote attacker to conduct spoofing attacks.
The vulnerability exists in IBM Security Identity Manager Virtual Appliance. A remote attacker with the ability to monitor communications on the network can spoof another user due to invalid session identifiers after the victim has logged out.
Successful exploitation of this vulnerability may result in disclosure of user information.
Remediation
Install update from vendor's website.