CVE-2016-9703

EUVD-2016-10504
IBM Security Identity Manager Virtual Appliance does not invalidate session tokens which could allow an unauthorized user with physical access to the work station to obtain sensitive information.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.4 LOW
PHYSICAL
LOW
NONE
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 19%
Affected Products (NVD)
VendorProductVersion
ibmsecurity_identity_manager_virtual_appliance
7.0.0.0
ibmsecurity_identity_manager_virtual_appliance
7.0.0.1
ibmsecurity_identity_manager_virtual_appliance
7.0.0.2
ibmsecurity_identity_manager_virtual_appliance
7.0.0.3
ibmsecurity_identity_manager_virtual_appliance
7.0.1.0
ibmsecurity_identity_manager_virtual_appliance
7.0.1.1
ibmsecurity_identity_manager_virtual_appliance
7.0.1.2
ibmsecurity_identity_manager_virtual_appliance
7.0.1.3
ibmsecurity_identity_manager_virtual_appliance
7.0.1.4
𝑥
= Vulnerable software versions