PT-2019-9949 · Ibm · Ibm Websphere Application Server
Publicado
2019-02-19
·
Atualizado
2020-08-24
·
CVE-2018-1996
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM WebSphere Application Server versions 7.0 through 9.0
Description
The issue is caused by improper TLS configuration, which could provide weaker than expected security. A remote attacker could exploit this to obtain sensitive information using man-in-the-middle techniques.
Recommendations
For versions 7.0 through 9.0, update the TLS configuration to ensure proper security settings are in place to prevent man-in-the-middle attacks.
Correção
Use of a Broken Cryptographic Algorithm
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Websphere Application Server