VULNERABILITY INTELLIGENCE
CVE-2016-2945
CVSS score7.5 HIGH
EPSS probability1.85%
CISA KEVNot currently listed
Published2016-07-08
Last modified2026-06-17
CVSS vectorCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
The API Discovery implementation in IBM WebSphere Application Server (WAS) 8.5.5.8 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 allows remote authenticated users to gain privileges via an external reference in a Swagger document.
Weakness classification
- nvd@nist.gov: CWE-264