IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 does not require SSL, which allows remote attackers to obtain sensitive cleartext information by sniffing the network.
References
Link | Resource |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg1LO90268 | Broken Link |
http://www-01.ibm.com/support/docview.wss?uid=swg1LO90295 | Broken Link |
http://www-01.ibm.com/support/docview.wss?uid=swg21990888 | Patch Vendor Advisory |
http://www.securityfocus.com/bid/94415 | Third Party Advisory VDB Entry |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: ibm
Published: 2016-11-30T11:00:00
Updated: 2016-11-30T10:57:01
Reserved: 2016-03-09T00:00:00
Link: CVE-2016-2953
JSON object: View
NVD Information
Status : Analyzed
Published: 2016-11-30T11:59:16.403
Modified: 2016-11-30T20:35:59.667
Link: CVE-2016-2953
JSON object: View
Redhat Information
No data.
CWE