PatchSiren cyber security CVE debrief
CVE-2016-9703 IBM CVE debrief
CVE-2016-9703 is a low-severity IBM Security Identity Manager Virtual Appliance issue in which session tokens are not invalidated properly. According to the CVE/NVD record, an unauthorized user with physical access to the workstation could use that weakness to obtain sensitive information. The vulnerable IBM Security Identity Manager Virtual Appliance versions listed by NVD span 7.0.0.0 through 7.0.1.4.
- Vendor
- IBM
- Product
- Security Identity Manager Virtual Appliance
- CVSS
- LOW 2.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-01
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-01
- Advisory updated
- 2026-05-13
Who should care
Administrators and operators of IBM Security Identity Manager Virtual Appliance deployments, especially where workstations may be shared, unattended, or physically accessible to non-administrators.
Technical summary
The NVD description states that the appliance does not invalidate session tokens. NVD maps the issue to CWE-384 and lists affected IBM Security Identity Manager Virtual Appliance versions 7.0.0.0, 7.0.0.1, 7.0.0.2, 7.0.0.3, 7.0.1.0, 7.0.1.1, 7.0.1.2, 7.0.1.3, and 7.0.1.4. The published CVSS vector is CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N, reflecting a physically reachable attack path with limited confidentiality impact.
Defensive priority
Low. The issue requires physical access and is described as confidentiality-only impact, but it still matters in shared-console or kiosk-like environments.
Recommended defensive actions
- Apply the IBM remediation referenced in the vendor advisory.
- Restrict physical access to affected workstations and consoles.
- Ensure users fully log out of sessions when leaving a workstation unattended.
- Review shared-device and kiosk policies for any environment running the affected appliance.
- Verify whether any deployed IBM Security Identity Manager Virtual Appliance instances match the affected versions listed by NVD.
Evidence notes
The summary is based on the CVE/NVD record and the IBM PSIRT vendor advisory reference. NVD marks the vulnerability as modified on 2026-05-13 and shows the CVE was published on 2017-02-01. The record includes IBM’s advisory reference and lists affected versions 7.0.0.0 through 7.0.1.4. The CVSS vector and CWE mapping were taken from the NVD metadata.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-9703 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-9703
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-9703 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-9703
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.