IBM Security Access Manager for Web is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements which could allow the attacker to view information in the back-end database.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3046
Reference (s):
- BID:95104
- URL: http://www.securityfocus.com/bid/95104
- http://www.ibm.com/support/docview.wss?uid=swg21995527