PT-2019-9949 · Ibm · Ibm Websphere Application Server
Published
2019-02-19
·
Updated
2020-08-24
·
CVE-2018-1996
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM WebSphere Application Server versions 7.0 through 9.0
Description
The issue is caused by improper TLS configuration, which could provide weaker than expected security. A remote attacker could exploit this to obtain sensitive information using man-in-the-middle techniques.
Recommendations
For versions 7.0 through 9.0, update the TLS configuration to ensure proper security settings are in place to prevent man-in-the-middle attacks.
Fix
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Websphere Application Server