PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-8912 IBM CVE debrief

CVE-2016-8912 is an information-disclosure issue in IBM Kenexa LMS on Cloud. According to the NVD record, affected versions include IBM Kenexa LMS on Cloud 13.1 and 13.2 through 13.2.4, where potentially sensitive information can be stored in log files and read by an authenticated user. The issue is rated CVSS 4.3 (Medium) and maps to CWE-532 (Insertion of Sensitive Information into Log File).

Vendor
IBM
Product
CVE-2016-8912
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-01
Original CVE updated
2026-05-13
Advisory published
2017-02-01
Advisory updated
2026-05-13

Who should care

IBM Kenexa LMS on Cloud administrators, application owners, security teams, and anyone responsible for log management or access control in environments running the affected versions.

Technical summary

The vulnerability is a log-file information disclosure: sensitive data may be written to logs and later accessible to users who already have authentication to the application. NVD lists CWE-532 and a CVSS v3.0 vector of AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N, indicating network-reachable exposure that requires low privileges and affects confidentiality only. The affected CPEs in the NVD record cover IBM Kenexa LMS on Cloud 13.1, 13.2, 13.2.2, 13.2.3, and 13.2.4.

Defensive priority

Medium. The confidentiality impact is limited, but the exposure can still leak credentials, identifiers, or other sensitive operational data if they are written to logs. Prioritize if the application handles regulated or high-value user data.

Recommended defensive actions

  • Review IBM’s vendor advisory and apply any IBM-recommended remediation for the affected Kenexa LMS on Cloud versions.
  • Restrict log file access to the minimum required administrators and service accounts.
  • Audit application and system logs for sensitive data exposure and remove or suppress secrets, tokens, passwords, and personal data from logging.
  • Rotate any credentials or secrets that may have been captured in logs.
  • Verify that only supported and remediated IBM Kenexa LMS on Cloud versions are deployed, especially if running 13.1 through 13.2.4.

Evidence notes

The NVD record states that IBM Kenexa LMS on Cloud 13.1 and 13.2-13.2.4 may store potentially sensitive information in log files readable by an authenticated user. The record also identifies CWE-532 and CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N. Official references listed in the source corpus include IBM’s advisory and the NVD/CVE records.

Official resources

Publicly disclosed in the NVD record on 2017-02-01. The supplied source corpus shows a later metadata modification date, but the CVE issue date should be treated as the published date above.