Описание
IBM Security Guardium 9.0, 9.1, 9.5, 10.0, and 10.1 transmits sensitive data in cleartext in the query of the request. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 110409
Ссылки
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:ibm:security_guardium:9.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_guardium:9.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_guardium:9.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_guardium:10.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_guardium:10.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_guardium:10.1.2:*:*:*:*:*:*:*
EPSS
Процентиль: 45%
0.00222
Низкий
3.7 Low
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-200
Связанные уязвимости
CVSS3: 3.7
github
больше 3 лет назад
IBM Security Guardium 9.0, 9.1, 9.5, 10.0, and 10.1 transmits sensitive data in cleartext in the query of the request. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 110409
EPSS
Процентиль: 45%
0.00222
Низкий
3.7 Low
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-200