PatchSiren cyber security CVE debrief
CVE-2016-6001 IBM CVE debrief
CVE-2016-6001 is a low-severity server-side request forgery (SSRF) issue in IBM Forms Experience Builder. According to NVD, the flaw can be triggered from the application design interface and may allow limited disclosure of internal resources. IBM’s referenced advisory and NVD list affected releases as 8.5, 8.5.1, and 8.6.0.
- Vendor
- IBM
- Product
- Forms Experience Builder
- CVSS
- LOW 3.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-01
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-01
- Advisory updated
- 2026-05-13
Who should care
Administrators and security teams responsible for IBM Forms Experience Builder deployments, especially environments that use the application design interface and allow the product to reach internal network resources.
Technical summary
NVD classifies the weakness as CWE-918 (SSRF) with CVSS v3.0 vector CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N. The issue is exposed over the network, requires low privileges, and is described as allowing some information disclosure of internal resources rather than direct integrity or availability impact. The affected CPEs listed by NVD are IBM Forms Experience Builder 8.5, 8.5.1, and 8.6.0.
Defensive priority
Low
Recommended defensive actions
- Check whether IBM Forms Experience Builder 8.5, 8.5.1, or 8.6.0 is deployed in your environment.
- Review IBM’s advisory and apply the vendor-recommended patch or update referenced for this CVE.
- Restrict the application’s ability to reach internal or sensitive network destinations where practical.
- Monitor application and network logs for unusual outbound requests initiated through the design interface.
- Validate that any remediation prevents the application from being used as a path to internal resources.
Evidence notes
This debrief is based on the NVD CVE record, which lists IBM Forms Experience Builder as the affected product family and identifies CWE-918. The NVD record includes the vendor reference to IBM’s advisory (swg21991280) and a third-party advisory entry at SecurityFocus BID 95777. The CVE was published on 2017-02-01 and later modified on 2026-05-13; those dates are used here only as record timeline context.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-6001 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-6001
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-6001 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-6001
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.