IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 does not require SSL, which allows remote attackers to obtain sensitive cleartext information by sniffing the network.
References
Link | Resource |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg1LO90295 | Broken Link |
http://www.securityfocus.com/bid/94415 | Third Party Advisory VDB Entry |
http://www-01.ibm.com/support/docview.wss?uid=swg21990888 | Patch Vendor Advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg1LO90268 | Broken Link |
Configurations
Configuration 1 (hide)
|
Information
Published : 2016-11-30 03:59
Updated : 2016-11-30 12:35
NVD link : CVE-2016-2953
Mitre link : CVE-2016-2953
JSON object : View
CWE
CWE-310
Cryptographic Issues
Products Affected
ibm
- connections