PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-6001 IBM CVE debrief

CVE-2016-6001 is a low-severity server-side request forgery (SSRF) issue in IBM Forms Experience Builder. According to NVD, the flaw can be triggered from the application design interface and may allow limited disclosure of internal resources. IBM’s referenced advisory and NVD list affected releases as 8.5, 8.5.1, and 8.6.0.

Vendor
IBM
Product
Forms Experience Builder
CVSS
LOW 3.1
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-01
Original CVE updated
2026-05-13
Advisory published
2017-02-01
Advisory updated
2026-05-13

Who should care

Administrators and security teams responsible for IBM Forms Experience Builder deployments, especially environments that use the application design interface and allow the product to reach internal network resources.

Technical summary

NVD classifies the weakness as CWE-918 (SSRF) with CVSS v3.0 vector CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N. The issue is exposed over the network, requires low privileges, and is described as allowing some information disclosure of internal resources rather than direct integrity or availability impact. The affected CPEs listed by NVD are IBM Forms Experience Builder 8.5, 8.5.1, and 8.6.0.

Defensive priority

Low

Recommended defensive actions

  • Check whether IBM Forms Experience Builder 8.5, 8.5.1, or 8.6.0 is deployed in your environment.
  • Review IBM’s advisory and apply the vendor-recommended patch or update referenced for this CVE.
  • Restrict the application’s ability to reach internal or sensitive network destinations where practical.
  • Monitor application and network logs for unusual outbound requests initiated through the design interface.
  • Validate that any remediation prevents the application from being used as a path to internal resources.

Evidence notes

This debrief is based on the NVD CVE record, which lists IBM Forms Experience Builder as the affected product family and identifies CWE-918. The NVD record includes the vendor reference to IBM’s advisory (swg21991280) and a third-party advisory entry at SecurityFocus BID 95777. The CVE was published on 2017-02-01 and later modified on 2026-05-13; those dates are used here only as record timeline context.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-6001 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-6001

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-6001 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-6001

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.