PatchSiren cyber security CVE debrief
CVE-2016-8912 IBM CVE debrief
CVE-2016-8912 is an information-disclosure issue in IBM Kenexa LMS on Cloud. According to the NVD record, affected versions include IBM Kenexa LMS on Cloud 13.1 and 13.2 through 13.2.4, where potentially sensitive information can be stored in log files and read by an authenticated user. The issue is rated CVSS 4.3 (Medium) and maps to CWE-532 (Insertion of Sensitive Information into Log File).
- Vendor
- IBM
- Product
- CVE-2016-8912
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-01
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-01
- Advisory updated
- 2026-05-13
Who should care
IBM Kenexa LMS on Cloud administrators, application owners, security teams, and anyone responsible for log management or access control in environments running the affected versions.
Technical summary
The vulnerability is a log-file information disclosure: sensitive data may be written to logs and later accessible to users who already have authentication to the application. NVD lists CWE-532 and a CVSS v3.0 vector of AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N, indicating network-reachable exposure that requires low privileges and affects confidentiality only. The affected CPEs in the NVD record cover IBM Kenexa LMS on Cloud 13.1, 13.2, 13.2.2, 13.2.3, and 13.2.4.
Defensive priority
Medium. The confidentiality impact is limited, but the exposure can still leak credentials, identifiers, or other sensitive operational data if they are written to logs. Prioritize if the application handles regulated or high-value user data.
Recommended defensive actions
- Review IBM’s vendor advisory and apply any IBM-recommended remediation for the affected Kenexa LMS on Cloud versions.
- Restrict log file access to the minimum required administrators and service accounts.
- Audit application and system logs for sensitive data exposure and remove or suppress secrets, tokens, passwords, and personal data from logging.
- Rotate any credentials or secrets that may have been captured in logs.
- Verify that only supported and remediated IBM Kenexa LMS on Cloud versions are deployed, especially if running 13.1 through 13.2.4.
Evidence notes
The NVD record states that IBM Kenexa LMS on Cloud 13.1 and 13.2-13.2.4 may store potentially sensitive information in log files readable by an authenticated user. The record also identifies CWE-532 and CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N. Official references listed in the source corpus include IBM’s advisory and the NVD/CVE records.
Official resources
-
CVE-2016-8912 CVE record
CVE.org
-
CVE-2016-8912 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
[email protected] - Third Party Advisory, VDB Entry
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
Publicly disclosed in the NVD record on 2017-02-01. The supplied source corpus shows a later metadata modification date, but the CVE issue date should be treated as the published date above.