The Teiid Java Database Connectivity (JDBC) socket, as used in JBoss Enterprise Data Services Platform before 5.3.0, does not encrypt login messages by default contrary to documentation and specification, which allows remote attackers to obtain login credentials via a man-in-the-middle (MITM) attack.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2012-11-23T20:00:00

Updated: 2017-08-28T12:57:01

Reserved: 2012-06-14T00:00:00


Link: CVE-2012-3431

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2012-11-23T20:55:02.960

Modified: 2017-08-29T01:31:55.337


Link: CVE-2012-3431

JSON object: View

cve-icon Redhat Information

No data.

CWE