← All CVEs

CVE-2016-2960

low · 3.7

IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.0.x before 8.0.0.13, 8.5.0.x before 8.5.5.10, 8.5.0.x and 16.0.0.x Liberty before Liberty Fix Pack 16.0.0.3, and 9.0.0.x before 9.0.0.1 allows remote attackers to cause a denial of service via crafted SIP messages.

3.7
CVSS
39.6%
EPSS (exploit prob.)
99th
EPSS percentile
2016-08-08
Published

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

Weaknesses

CWE-284

Affected products

VendorProductAffected versions
ibmwebsphere_application_server7.0
ibmwebsphere_application_server7.0.0.0
ibmwebsphere_application_server7.0.0.1
ibmwebsphere_application_server7.0.0.2
ibmwebsphere_application_server7.0.0.3
ibmwebsphere_application_server7.0.0.4
ibmwebsphere_application_server7.0.0.5
ibmwebsphere_application_server7.0.0.6
ibmwebsphere_application_server7.0.0.7
ibmwebsphere_application_server7.0.0.8
ibmwebsphere_application_server7.0.0.9
ibmwebsphere_application_server7.0.0.10
ibmwebsphere_application_server7.0.0.11
ibmwebsphere_application_server7.0.0.12
ibmwebsphere_application_server7.0.0.13
ibmwebsphere_application_server7.0.0.14
ibmwebsphere_application_server7.0.0.15
ibmwebsphere_application_server7.0.0.16
ibmwebsphere_application_server7.0.0.17
ibmwebsphere_application_server7.0.0.18
ibmwebsphere_application_server7.0.0.19
ibmwebsphere_application_server7.0.0.21
ibmwebsphere_application_server7.0.0.22
ibmwebsphere_application_server7.0.0.23
ibmwebsphere_application_server7.0.0.24
ibmwebsphere_application_server7.0.0.25
ibmwebsphere_application_server7.0.0.27
ibmwebsphere_application_server7.0.0.28
ibmwebsphere_application_server7.0.0.29
ibmwebsphere_application_server7.0.0.31
ibmwebsphere_application_server7.0.0.32
ibmwebsphere_application_server7.0.0.33
ibmwebsphere_application_server7.0.0.34
ibmwebsphere_application_server7.0.0.35
ibmwebsphere_application_server7.0.0.36
ibmwebsphere_application_server7.0.0.37
ibmwebsphere_application_server7.0.0.38
ibmwebsphere_application_server7.0.0.39
ibmwebsphere_application_server7.0.0.41
ibmwebsphere_application_server8.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-2960