PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-0310 IBM CVE debrief

CVE-2016-0310 is an IBM Connections issue in which a maliciously influenced Host header can cause users to be navigated to an attacker-controlled domain. The public CVE record was published on 2017-02-08 and later modified on 2026-05-13. NVD lists IBM Connections 4.0, 4.5, 5.0, and 5.5 as vulnerable, with a medium-severity CVSS 3.0 vector that includes network access and user interaction.

Vendor
IBM
Product
Connections
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-08
Original CVE updated
2026-05-13
Advisory published
2017-02-08
Advisory updated
2026-05-13

Who should care

IBM Connections administrators, web application owners, reverse proxy/load balancer teams, and security teams responsible for validating request headers and external redirects.

Technical summary

The issue is described as a possible host header injection attack in IBM Connections that can influence navigation to an attacker’s domain. In the supplied NVD data, the attack vector is network-based, requires low privileges and user interaction, and is scored as CVSS 3.0 AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N. NVD also maps the weakness to CWE-79 in the record provided.

Defensive priority

Medium. The issue can affect user trust and redirect traffic to attacker-controlled destinations, so it is worth remediating promptly, especially in externally reachable deployments.

Recommended defensive actions

  • Apply the IBM fix or mitigation referenced in the vendor advisory for CVE-2016-0310.
  • Review any application, proxy, or load balancer logic that accepts or forwards the Host header and ensure only expected hostnames are accepted.
  • Validate that generated links, redirects, and canonical URL handling do not depend on untrusted Host header values.
  • Monitor for unexpected redirects or navigation to non-canonical domains in IBM Connections workflows.
  • Confirm which IBM Connections versions are deployed and prioritize systems matching the affected NVD CPEs (4.0, 4.5, 5.0, and 5.5).

Evidence notes

All substantive claims in this debrief come from the supplied NVD record and the referenced IBM vendor advisory/BID links. The CVE was published on 2017-02-08 and last modified on 2026-05-13. The supplied corpus does not identify a KEV listing.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-0310 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-0310

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-0310 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-0310

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.