PatchSiren cyber security CVE debrief
CVE-2016-8929 IBM CVE debrief
CVE-2016-8929 is a medium-severity SQL injection issue in IBM Kenexa LMS on Cloud. According to NVD, the flaw can let an attacker influence back-end database operations and potentially view, add, modify, or delete data. The NVD record maps the issue to CWE-89 and lists multiple affected IBM Kenexa LMS versions. IBM vendor guidance is referenced in the NVD record.
- Vendor
- IBM
- Product
- CVE-2016-8929
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-01
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-01
- Advisory updated
- 2026-05-13
Who should care
Administrators, security teams, and application owners running IBM Kenexa LMS on Cloud, especially the affected versions listed in NVD (4.1, 4.2, 4.2.2, 4.2.3, 4.2.4, 5.0, 5.1, and 5.2).
Technical summary
NVD classifies the flaw as CWE-89 SQL injection with CVSS 3.0 vector AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L, indicating network reachability, low attack complexity, and required low privileges. The record states that specially crafted SQL statements could affect database confidentiality and integrity. Vulnerable CPEs in the source include IBM Kenexa LMS versions 4.1 through 5.2.
Defensive priority
Medium priority. The CVSS score is 5.4, and the issue requires low privileges, but it can still affect database data integrity and availability. Remediation should be scheduled promptly for any exposed or actively used deployment.
Recommended defensive actions
- Confirm whether any IBM Kenexa LMS instances match the affected versions listed by NVD.
- Apply the IBM remediation referenced in the vendor advisory linked from the NVD record.
- Review application input handling and database access controls for SQL injection risk reduction.
- Monitor application and database logs for unusual queries or unexpected data modification activity.
- Restrict access to the application and limit user privileges where possible until remediation is complete.
Evidence notes
This debrief is based on the supplied NVD record published on 2017-02-01 and last modified on 2026-05-13, plus the linked IBM advisory and SecurityFocus entry referenced in the source metadata. The source specifies affected IBM Kenexa LMS versions, CVSS 3.0 vector CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L, and CWE-89. No KEV entry was provided in the supplied corpus.
Official resources
-
CVE-2016-8929 CVE record
CVE.org
-
CVE-2016-8929 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Patch, Vendor Advisory
-
Mitigation or vendor reference
[email protected] - Third Party Advisory, VDB Entry
Publicly disclosed on 2017-02-01 per the CVE/NVD record; the NVD entry was last modified on 2026-05-13.