4.3

CVE-2016-2960

IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.0.x before 8.0.0.13, 8.5.0.x before 8.5.5.10, 8.5.0.x and 16.0.0.x Liberty before Liberty Fix Pack 16.0.0.3, and 9.0.0.x before 9.0.0.1 allows remote attackers to cause a denial of service via crafted SIP messages.

Data is provided by the National Vulnerability Database (NVD)
IbmWebsphere Application Server Version7.0.0.0
IbmWebsphere Application Server Version7.0.0.1
IbmWebsphere Application Server Version7.0.0.2
IbmWebsphere Application Server Version7.0.0.3
IbmWebsphere Application Server Version7.0.0.4
IbmWebsphere Application Server Version7.0.0.5
IbmWebsphere Application Server Version7.0.0.6
IbmWebsphere Application Server Version7.0.0.7
IbmWebsphere Application Server Version7.0.0.8
IbmWebsphere Application Server Version7.0.0.9
IbmWebsphere Application Server Version7.0.0.10
IbmWebsphere Application Server Version7.0.0.11
IbmWebsphere Application Server Version7.0.0.12
IbmWebsphere Application Server Version7.0.0.13
IbmWebsphere Application Server Version7.0.0.14
IbmWebsphere Application Server Version7.0.0.15
IbmWebsphere Application Server Version7.0.0.16
IbmWebsphere Application Server Version7.0.0.17
IbmWebsphere Application Server Version7.0.0.18
IbmWebsphere Application Server Version7.0.0.19
IbmWebsphere Application Server Version7.0.0.21
IbmWebsphere Application Server Version7.0.0.22
IbmWebsphere Application Server Version7.0.0.23
IbmWebsphere Application Server Version7.0.0.24
IbmWebsphere Application Server Version7.0.0.25
IbmWebsphere Application Server Version7.0.0.27
IbmWebsphere Application Server Version7.0.0.28
IbmWebsphere Application Server Version7.0.0.29
IbmWebsphere Application Server Version7.0.0.31
IbmWebsphere Application Server Version7.0.0.32
IbmWebsphere Application Server Version7.0.0.33
IbmWebsphere Application Server Version7.0.0.34
IbmWebsphere Application Server Version7.0.0.35
IbmWebsphere Application Server Version7.0.0.36
IbmWebsphere Application Server Version7.0.0.37
IbmWebsphere Application Server Version7.0.0.38
IbmWebsphere Application Server Version7.0.0.39
IbmWebsphere Application Server Version7.0.0.41
IbmWebsphere Application Server Version8.0.0.0
IbmWebsphere Application Server Version8.0.0.1
IbmWebsphere Application Server Version8.0.0.2
IbmWebsphere Application Server Version8.0.0.3
IbmWebsphere Application Server Version8.0.0.4
IbmWebsphere Application Server Version8.0.0.5
IbmWebsphere Application Server Version8.0.0.6
IbmWebsphere Application Server Version8.0.0.7
IbmWebsphere Application Server Version8.0.0.8
IbmWebsphere Application Server Version8.0.0.9
IbmWebsphere Application Server Version8.0.0.10
IbmWebsphere Application Server Version8.0.0.11
IbmWebsphere Application Server Version8.0.0.12
IbmWebsphere Application Server Version8.5.0.0
IbmWebsphere Application Server Version8.5.0.0 Update- Editionliberty_profile
IbmWebsphere Application Server Version8.5.0.1 Update- Editionliberty_profile
IbmWebsphere Application Server Version8.5.0.2 Update- Editionliberty_profile
IbmWebsphere Application Server Version8.5.5.0 Update- Editionliberty_profile
IbmWebsphere Application Server Version8.5.5.1 Update- Editionliberty_profile
IbmWebsphere Application Server Version8.5.5.2 Update- Editionliberty_profile
IbmWebsphere Application Server Version8.5.5.4
IbmWebsphere Application Server Version8.5.5.5
IbmWebsphere Application Server Version8.5.5.6
IbmWebsphere Application Server Version8.5.5.7
IbmWebsphere Application Server Version8.5.5.8
IbmWebsphere Application Server Version8.5.5.9
IbmWebsphere Application Server Version9.0.0.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.68% 0.691
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 3.7 2.2 1.4
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.