PatchSiren cyber security CVE debrief
CVE-2016-8929 IBM CVE debrief
CVE-2016-8929 is a medium-severity SQL injection issue in IBM Kenexa LMS on Cloud. According to NVD, the flaw can let an attacker influence back-end database operations and potentially view, add, modify, or delete data. The NVD record maps the issue to CWE-89 and lists multiple affected IBM Kenexa LMS versions. IBM vendor guidance is referenced in the NVD record.
- Vendor
- IBM
- Product
- Kenexa Lms
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-01
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-01
- Advisory updated
- 2026-05-13
Who should care
Administrators, security teams, and application owners running IBM Kenexa LMS on Cloud, especially the affected versions listed in NVD (4.1, 4.2, 4.2.2, 4.2.3, 4.2.4, 5.0, 5.1, and 5.2).
Technical summary
NVD classifies the flaw as CWE-89 SQL injection with CVSS 3.0 vector AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L, indicating network reachability, low attack complexity, and required low privileges. The record states that specially crafted SQL statements could affect database confidentiality and integrity. Vulnerable CPEs in the source include IBM Kenexa LMS versions 4.1 through 5.2.
Defensive priority
Medium priority. The CVSS score is 5.4, and the issue requires low privileges, but it can still affect database data integrity and availability. Remediation should be scheduled promptly for any exposed or actively used deployment.
Recommended defensive actions
- Confirm whether any IBM Kenexa LMS instances match the affected versions listed by NVD.
- Apply the IBM remediation referenced in the vendor advisory linked from the NVD record.
- Review application input handling and database access controls for SQL injection risk reduction.
- Monitor application and database logs for unusual queries or unexpected data modification activity.
- Restrict access to the application and limit user privileges where possible until remediation is complete.
Evidence notes
This debrief is based on the supplied NVD record published on 2017-02-01 and last modified on 2026-05-13, plus the linked IBM advisory and SecurityFocus entry referenced in the source metadata. The source specifies affected IBM Kenexa LMS versions, CVSS 3.0 vector CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L, and CWE-89. No KEV entry was provided in the supplied corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-8929 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-8929
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-8929 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-8929
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.