CVE-2016-9717
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
31/07/2017
Last modified:
20/04/2025
Description
HTTP Parameter Override is identified in the IBM Infosphere Master Data Management (MDM) 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 product. It enables attackers by exposing the presence of duplicated parameters which may produce an anomalous behavior in the application that can be potentially exploited.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ibm:infosphere_master_data_management_server:10.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:infosphere_master_data_management_server:11.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:infosphere_master_data_management_server:11.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:infosphere_master_data_management_server:11.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:infosphere_master_data_management_server:11.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:infosphere_master_data_management_server:11.6:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.ibm.com/support/docview.wss?uid=swg22006605
- http://www.securityfocus.com/bid/100074
- https://exchange.xforce.ibmcloud.com/vulnerabilities/119730
- http://www.ibm.com/support/docview.wss?uid=swg22006605
- http://www.securityfocus.com/bid/100074
- https://exchange.xforce.ibmcloud.com/vulnerabilities/119730



