PT-2019-9949 · Ibm · Ibm Websphere Application Server

Published

2019-02-19

·

Updated

2020-08-24

·

CVE-2018-1996

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM WebSphere Application Server versions 7.0 through 9.0
Description The issue is caused by improper TLS configuration, which could provide weaker than expected security. A remote attacker could exploit this to obtain sensitive information using man-in-the-middle techniques.
Recommendations For versions 7.0 through 9.0, update the TLS configuration to ensure proper security settings are in place to prevent man-in-the-middle attacks.

Fix

Use of a Broken Cryptographic Algorithm

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1996

Affected Products

Ibm Websphere Application Server