VYPR
Low severity3.1NVD Advisory· Published Mar 20, 2017· Updated May 13, 2026

CVE-2016-9697

CVE-2016-9697

Description

IBM Rhapsody Design Manager 4.0, 5.0, and 6.0 allow a JSON Hijacking attack that exposes data passed between server and browser.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM Rhapsody Design Manager 4.0, 5.0, and 6.0 allow a JSON Hijacking attack that exposes data passed between server and browser.

Vulnerability

IBM Rhapsody Design Manager versions 4.0, 5.0, and 6.0 contain an unspecified vulnerability that could allow an attacker to perform a JSON Hijacking Attack [1]. This class of attack occurs when an attacker is able to intercept or otherwise access JSON data exchanged between the server and the browser, typically by exploiting the same-origin policy or by tricking the user into executing a malicious script that reads cross-origin JSON responses [1].

Exploitation

The attacker requires no authentication and can exploit the vulnerability over a network [1]. The exact mechanism is not disclosed in the available references, but typical JSON Hijacking attacks rely on the attacker being able to request a JSON resource from the victim's browser (e.g., via a crafted web page or a script) and access the data due to insufficient protections [1].

Impact

A successful JSON Hijacking attack may expose to an attacker information that is passed between the server and the browser [1]. The impact is limited to information disclosure of potentially sensitive data that is carried in JSON responses [1]. The CVSS v3 base score is 3.1 (Low) [1].

Mitigation

IBM has released a security bulletin referencing fix information for Rational Rhapsody Design Manager, but the specific fixed version is not explicitly stated in the available reference [1]. Customers are advised to consult the IBM support page for updates and apply the recommended fix from the vendor [1].

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Range: 4.0, 5.0, 6.0
  • IBM Corporation/Rational Rhapsody Design Managerv5
    Range: 4.0.2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.