← Vulnerability feed

Vulnerability record · CVE-2016-3034 · published 1 February 2017

CVE-2016-3034: Ibm security appscan source inadequate encryption strength vulnerability

Ibm · Security Appscan Source

IBM AppScan Source uses a one-way hash without salt to encrypt highly sensitive information, which could allow a local attacker to decrypt information more easily.

4.4 CVSS 3.0 Medium EPSS 0.21% · top 89.4% CWE-326 · Inadequate encryption strength
4.4CVSS 3.0 base score, v2 2.1
0.21%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

IBM AppScan Source uses a one-way hash without salt to encrypt highly sensitive information, which could allow a local attacker to decrypt information more easily.

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-3034 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-6120Ibm rational appscan source command injection vulnerabilityIBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, 9.…EPSS 5.0%9.3CVE-2014-6119Ibm security appscan code injection vulnerabilityIBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.…EPSS 3.6%7.2CVE-2014-3072Ibm security appscan source vulnerabilityUnspecified vulnerability in the Automation Server in IBM Security AppScan Source 8 through 8.0.0.2, 8.5 through 8.5.0.1, 8.6 through 8.6.0.2, 8.7 th…EPSS 0.37%5.8CVE-2012-2159Ibm security appscan source improper input validation vulnerabilityOpen redirect vulnerability in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x and 8.x before 8.6 and IBM SPSS Data Collec…EPSS 1.8%5.5CVE-2014-6122Ibm security appscan permissions and access controls vulnerabilityIBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.…EPSS 1.5%5.3CVE-2016-3035Ibm security appscan source information exposure vulnerabilityIBM AppScan Source could reveal some sensitive information through the browsing of testlinks on the server.EPSS 1.0%5.0CVE-2012-2173Ibm security appscan source vulnerabilityThe ODBC driver in IBM Security AppScan Source 7.x and 8.x before 8.6 sends an SHA-1 hash of the connection password during connections to a solidDB …EPSS 1.2%4.3CVE-2014-6135Ibm security appscan improper input validation vulnerabilityIBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2016-3034), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.