PT-2016-4137 · Ibm · Ibm Websphere Application Server

Publicado

2016-05-17

·

Atualizado

2016-11-28

·

CVE-2016-0306

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM WebSphere Application Server (WAS) versions 7.0 through 7.0.0.40 IBM WebSphere Application Server (WAS) versions 8.0 through 8.0.0.12 IBM WebSphere Application Server (WAS) versions 8.5 through 8.5.5.9
Description The issue is related to a misconfiguration of TLS when FIPS 140-2 is enabled, allowing man-in-the-middle attackers to obtain sensitive information via unspecified vectors.
Recommendations For IBM WebSphere Application Server (WAS) versions 7.0 through 7.0.0.40, update to version 7.0.0.41 or later. For IBM WebSphere Application Server (WAS) versions 8.0 through 8.0.0.12, update to version 8.0.0.13 or later. For IBM WebSphere Application Server (WAS) versions 8.5 through 8.5.5.9, update to version 8.5.5.10 or later.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-0306

Produtos afetados

Ibm Websphere Application Server