CVE-2016-0339

IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session identifiers after logout, which makes it easier for remote attackers to spoof users by leveraging knowledge of "traffic records."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.6 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
ibmCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 56%
VendorProductVersion
ibmsecurity_identity_manager_adapter
7.0.0.0
ibmsecurity_identity_manager_adapter
7.0.0.1
ibmsecurity_identity_manager_adapter
7.0.0.2
ibmsecurity_identity_manager_adapter
7.0.0.3
ibmsecurity_identity_manager_adapter
7.0.1.0
ibmsecurity_identity_manager_adapter
7.0.1.1
𝑥
= Vulnerable software versions