IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 does not require SSL, which allows remote attackers to obtain sensitive cleartext information by sniffing the network.
References
Link | Resource |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg1LO90268 | Broken Link |
http://www-01.ibm.com/support/docview.wss?uid=swg1LO90295 | Broken Link |
http://www-01.ibm.com/support/docview.wss?uid=swg21990888 | Patch Vendor Advisory |
http://www.securityfocus.com/bid/94415 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2016-11-30 11:59
Updated : 2016-11-30 20:35
NVD link : CVE-2016-2953
Mitre link : CVE-2016-2953
CVE.ORG link : CVE-2016-2953
JSON object : View
Products Affected
ibm
- connections
CWE
CWE-310
Cryptographic Issues