PT-2012-3846 · Ibm · Ibm Websphere Application Server
Publicado
2012-05-01
·
Atualizado
2017-08-29
·
CVE-2012-2162
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
IBM WebSphere Application Server (WAS) versions 8.0 and earlier
Description
The issue allows remote attackers to obtain sensitive information by sniffing the network or spoof arbitrary servers via a man-in-the-middle attack due to the use of unencrypted HTTP communication after the expiration of the plugin-key.kdb password.
Recommendations
For IBM WebSphere Application Server (WAS) versions 8.0 and earlier, update the plugin-key.kdb password to prevent the use of unencrypted HTTP communication.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Websphere Application Server