PatchSiren cyber security CVE debrief
CVE-2016-0310 IBM CVE debrief
CVE-2016-0310 is an IBM Connections issue in which a maliciously influenced Host header can cause users to be navigated to an attacker-controlled domain. The public CVE record was published on 2017-02-08 and later modified on 2026-05-13. NVD lists IBM Connections 4.0, 4.5, 5.0, and 5.5 as vulnerable, with a medium-severity CVSS 3.0 vector that includes network access and user interaction.
- Vendor
- IBM
- Product
- CVE-2016-0310
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-08
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-08
- Advisory updated
- 2026-05-13
Who should care
IBM Connections administrators, web application owners, reverse proxy/load balancer teams, and security teams responsible for validating request headers and external redirects.
Technical summary
The issue is described as a possible host header injection attack in IBM Connections that can influence navigation to an attacker’s domain. In the supplied NVD data, the attack vector is network-based, requires low privileges and user interaction, and is scored as CVSS 3.0 AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N. NVD also maps the weakness to CWE-79 in the record provided.
Defensive priority
Medium. The issue can affect user trust and redirect traffic to attacker-controlled destinations, so it is worth remediating promptly, especially in externally reachable deployments.
Recommended defensive actions
- Apply the IBM fix or mitigation referenced in the vendor advisory for CVE-2016-0310.
- Review any application, proxy, or load balancer logic that accepts or forwards the Host header and ensure only expected hostnames are accepted.
- Validate that generated links, redirects, and canonical URL handling do not depend on untrusted Host header values.
- Monitor for unexpected redirects or navigation to non-canonical domains in IBM Connections workflows.
- Confirm which IBM Connections versions are deployed and prioritize systems matching the affected NVD CPEs (4.0, 4.5, 5.0, and 5.5).
Evidence notes
All substantive claims in this debrief come from the supplied NVD record and the referenced IBM vendor advisory/BID links. The CVE was published on 2017-02-08 and last modified on 2026-05-13. The supplied corpus does not identify a KEV listing.
Official resources
-
CVE-2016-0310 CVE record
CVE.org
-
CVE-2016-0310 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Patch, Vendor Advisory
- Source reference
Public CVE record published on 2017-02-08; NVD record last modified on 2026-05-13. No KEV information is present in the supplied corpus.