CVE-2016-2908
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 3.4%
exploitation probability
3.4%top 12% of all CVEs
observed exploitation
nono source reports it
IBM Single Sign On for Bluemix could allow a remote attacker to obtain sensitive information, caused by a XML external entity (XXE) error when processing XML data by the XML parser. A remote attacker could exploit this vulnerability to read arbitrary files on the system or cause a denial of service.
Affected products
IBM Corporation · Access Manager