Show plain JSON{"id": "CVE-2016-0240", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.3, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 3.7, "attackVector": "NETWORK", "baseSeverity": "LOW", "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "HIGH", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "LOW"}, "impactScore": 1.4, "exploitabilityScore": 2.2}]}, "published": "2016-10-22T03:59:01.813", "references": [{"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21990232", "tags": ["Patch", "VDB Entry"], "source": "psirt@us.ibm.com"}, {"url": "http://www.securityfocus.com/bid/93836", "source": "psirt@us.ibm.com"}, {"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21990232", "tags": ["Patch", "VDB Entry"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/bid/93836", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-254"}]}], "descriptions": [{"lang": "en", "value": "IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by leveraging use of HTTP."}, {"lang": "es", "value": "IBM Security Guardium Database Activity Monitor 8.2 en versiones anteriores a p310, 9.x hasta la versi\u00f3n 9.5 en versiones anteriores a p700 y 10.x hasta la versi\u00f3n 10.1 en versiones anteriores a p100 no habilita el mecanismo de protecci\u00f3n HSTS, lo que hace que sea m\u00e1s f\u00e1cil para atacantes remotos obtener informaci\u00f3n sensible aprovechando el uso de HTTP."}], "lastModified": "2025-04-12T10:46:40.837", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:8.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4748C865-7E2C-4446-9F95-1E4979F9790A"}, {"criteria": "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:9.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E0C93CAD-AD59-48CA-82E4-4FAE19E3E144"}, {"criteria": "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:9.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "408106A6-2C6A-4593-B5FC-F358048F3B90"}, {"criteria": "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:9.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4F037EDD-2E76-41FA-B566-B73670FA3009"}, {"criteria": "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:10.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "29D81340-4C19-4425-8C66-49DD3455EDFA"}, {"criteria": "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:10.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "812ADB6B-451E-41E6-938A-D21E97FB5014"}, {"criteria": "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:10.01:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5CB6807E-EFEB-4753-ACF3-832918D23939"}], "operator": "OR"}]}], "sourceIdentifier": "psirt@us.ibm.com"}