PT-2012-4706 · Teiid · Teiid Java Database Connectivity (Jdbc) Socket

David Jorm

+1

·

Publicado

2012-11-23

·

Atualizado

2017-08-29

·

CVE-2012-3431

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Teiid Java Database Connectivity (JDBC) socket versions prior to 5.3.0
Description The issue allows remote attackers to obtain login credentials via a man-in-the-middle (MITM) attack because login messages are not encrypted by default, contrary to documentation and specification.
Recommendations For versions prior to 5.3.0, update to version 5.3.0 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-3431

Produtos afetados

Teiid Java Database Connectivity (Jdbc) Socket