First published: Wed Jul 05 2017(Updated: )
IBM Security Guardium 9.0, 9.1, 9.5, 10.0, and 10.1 transmits sensitive data in cleartext in the query of the request. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 110409
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Guardium z/OS | =9.0 | |
IBM InfoSphere Guardium z/OS | =9.1 | |
IBM InfoSphere Guardium z/OS | =9.5 | |
IBM InfoSphere Guardium z/OS | =10.0 | |
IBM InfoSphere Guardium z/OS | =10.1 | |
IBM InfoSphere Guardium z/OS | =10.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0238 has a medium severity rating due to the potential exposure of sensitive data.
To mitigate CVE-2016-0238, ensure that sensitive data is transmitted over secure protocols like TLS.
CVE-2016-0238 affects IBM Security Guardium versions 9.0, 9.1, 9.5, 10.0, and 10.1.
Attackers can use man-in-the-middle techniques to exploit CVE-2016-0238 and capture cleartext sensitive information.
IBM has released updates to address the vulnerabilities associated with CVE-2016-0238, so check for the latest software updates.