CVE-2012-3312: Medium severity ibm infosphere guardium database activity monitoring vulnerability
The datasource definition editor in IBM InfoSphere Guardium 8.2 and earlier, when the save-password setting is enabled, transmits cleartext database credentials, which allows remote attackers to obtain sensitive information by sniffing the network.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3312?
CVE-2012-3312 is rated as a high severity vulnerability due to the exposure of cleartext database credentials.
How do I fix CVE-2012-3312?
To fix CVE-2012-3312, disable the save-password setting in the datasource definition editor to prevent transmission of cleartext credentials.
What software versions are affected by CVE-2012-3312?
CVE-2012-3312 affects IBM InfoSphere Guardium versions 8.0, 8.1, and 8.2.
Can CVE-2012-3312 lead to unauthorized access?
Yes, CVE-2012-3312 can lead to unauthorized access as attackers can sniff the network and capture sensitive database credentials.
Is CVE-2012-3312 a network vulnerability?
Yes, CVE-2012-3312 is considered a network vulnerability since it involves the capture of credentials transmitted in cleartext over the network.