First published: Wed Aug 29 2012(Updated: )
The datasource definition editor in IBM InfoSphere Guardium 8.2 and earlier, when the save-password setting is enabled, transmits cleartext database credentials, which allows remote attackers to obtain sensitive information by sniffing the network.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Guardium Database Activity Monitoring | <=8.2 | |
IBM InfoSphere Guardium Database Activity Monitoring | =8.00 | |
IBM InfoSphere Guardium Database Activity Monitoring | =8.01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3312 is rated as a high severity vulnerability due to the exposure of cleartext database credentials.
To fix CVE-2012-3312, disable the save-password setting in the datasource definition editor to prevent transmission of cleartext credentials.
CVE-2012-3312 affects IBM InfoSphere Guardium versions 8.0, 8.1, and 8.2.
Yes, CVE-2012-3312 can lead to unauthorized access as attackers can sniff the network and capture sensitive database credentials.
Yes, CVE-2012-3312 is considered a network vulnerability since it involves the capture of credentials transmitted in cleartext over the network.