CVE-2016-0323: IBM Bluemix

Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.

The Auto-Scaling agent in Liberty for Java in IBM Bluemix before 2.7-20160321-1358 allows remote authenticated users to disable X.509 certificate validation, and consequently bypass an intended HTTPS trust-management feature, via unspecified vectors.

Affected products

  • IBM Bluemix: affected versions not specified

Published 2016-05-17. Last modified 2026-06-17.