Vulnerability Description
IBM Security Guardium 9.0, 9.1, 9.5, 10.0, and 10.1 transmits sensitive data in cleartext in the query of the request. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 110409
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Security Guardium | 9.0 |
Related Weaknesses (CWE)
References
- http://www.ibm.com/support/docview.wss?uid=swg21989124Vendor Advisory
- http://www.securityfocus.com/bid/99379Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/110409Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg21989124Vendor Advisory
- http://www.securityfocus.com/bid/99379Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/110409Vendor Advisory
FAQ
What is CVE-2016-0238?
CVE-2016-0238 is a vulnerability with a CVSS score of 3.7 (LOW). IBM Security Guardium 9.0, 9.1, 9.5, 10.0, and 10.1 transmits sensitive data in cleartext in the query of the request. This could allow an attacker to obtain sensitive information using man in the mid...
How severe is CVE-2016-0238?
CVE-2016-0238 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-0238?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Security Guardium.