PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-8929 IBM CVE debrief

CVE-2016-8929 is a medium-severity SQL injection issue in IBM Kenexa LMS on Cloud. According to NVD, the flaw can let an attacker influence back-end database operations and potentially view, add, modify, or delete data. The NVD record maps the issue to CWE-89 and lists multiple affected IBM Kenexa LMS versions. IBM vendor guidance is referenced in the NVD record.

Vendor
IBM
Product
CVE-2016-8929
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-01
Original CVE updated
2026-05-13
Advisory published
2017-02-01
Advisory updated
2026-05-13

Who should care

Administrators, security teams, and application owners running IBM Kenexa LMS on Cloud, especially the affected versions listed in NVD (4.1, 4.2, 4.2.2, 4.2.3, 4.2.4, 5.0, 5.1, and 5.2).

Technical summary

NVD classifies the flaw as CWE-89 SQL injection with CVSS 3.0 vector AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L, indicating network reachability, low attack complexity, and required low privileges. The record states that specially crafted SQL statements could affect database confidentiality and integrity. Vulnerable CPEs in the source include IBM Kenexa LMS versions 4.1 through 5.2.

Defensive priority

Medium priority. The CVSS score is 5.4, and the issue requires low privileges, but it can still affect database data integrity and availability. Remediation should be scheduled promptly for any exposed or actively used deployment.

Recommended defensive actions

  • Confirm whether any IBM Kenexa LMS instances match the affected versions listed by NVD.
  • Apply the IBM remediation referenced in the vendor advisory linked from the NVD record.
  • Review application input handling and database access controls for SQL injection risk reduction.
  • Monitor application and database logs for unusual queries or unexpected data modification activity.
  • Restrict access to the application and limit user privileges where possible until remediation is complete.

Evidence notes

This debrief is based on the supplied NVD record published on 2017-02-01 and last modified on 2026-05-13, plus the linked IBM advisory and SecurityFocus entry referenced in the source metadata. The source specifies affected IBM Kenexa LMS versions, CVSS 3.0 vector CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L, and CWE-89. No KEV entry was provided in the supplied corpus.

Official resources

Publicly disclosed on 2017-02-01 per the CVE/NVD record; the NVD entry was last modified on 2026-05-13.