CVE-2016-3028
9.1
CRITICAL · CVSS 3.0 · EPSS 3.5% (pctl 89)
In your normal cycle
Critical by CVSS (9.1), but no sign of active exploitation.
Description
IBM Security Access Manager for Web 7.0 before IF2 and 8.0 before 8.0.1.4 IF3 and Security Access Manager 9.0 before 9.0.1.0 IF5 allow remote authenticated users to execute arbitrary commands by leveraging LMI admin access.
Scoring
| CVSS | 9.1 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 3.54% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2016-11-25 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| ibm | security access manager |
| ibm | security access manager for web |
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV89257
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV89322
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV89326
- http://www-01.ibm.com/support/docview.wss?uid=swg21990317
- http://www.securityfocus.com/bid/93176
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV89257
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV89322
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV89326
- http://www-01.ibm.com/support/docview.wss?uid=swg21990317
- http://www.securityfocus.com/bid/93176
→ the Explorer · watch your stack · NVD