CVE-2016-0389 describes an information disclosure vulnerability in the Admin Center of IBM WebSphere Application Server (WAS) Liberty, specifically versions 8.5.5.2 through 8.5.5.9 before Fix Pack 16.0.0.2. This medium-severity vulnerability, rated 5.3 CVSSv3, allows remote attackers to obtain sensitive information without authentication or user interaction. While the vulnerability has a low EPSS score and no known public exploits, Metasploit modules, or community discussion, organizations using affected WAS Liberty versions should apply the recommended fix pack to mitigate potential risks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.5.5.2CPE matchmatch criteria | cpe:2.3:a:ibm:websphere_application_server:8.5.5.2:*:*:*:liberty:*:*:* | ||
8.5.5.3CPE matchmatch criteria | cpe:2.3:a:ibm:websphere_application_server:8.5.5.3:*:*:*:liberty:*:*:* | ||
8.5.5.4CPE matchmatch criteria | cpe:2.3:a:ibm:websphere_application_server:8.5.5.4:*:*:*:liberty:*:*:* | ||
8.5.5.5CPE matchmatch criteria | cpe:2.3:a:ibm:websphere_application_server:8.5.5.5:*:*:*:liberty:*:*:* | ||
8.5.5.6CPE matchmatch criteria | cpe:2.3:a:ibm:websphere_application_server:8.5.5.6:*:*:*:liberty:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.