First published: Mon Sep 26 2016(Updated: )
IBM Security Guardium 9.0 before p700 and 10.0 before p100 allows man-in-the-middle attackers to obtain sensitive query-string information from SSL sessions via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Guardium z/OS | =9.0 | |
IBM InfoSphere Guardium z/OS | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0248 has a medium severity rating due to its potential to allow man-in-the-middle attacks.
To fix CVE-2016-0248, upgrade IBM Security Guardium to version 9.0 p700 or 10.0 p100 or later.
CVE-2016-0248 allows man-in-the-middle attackers to capture sensitive query-string information from SSL sessions.
CVE-2016-0248 affects IBM Security Guardium versions 9.0 before p700 and 10.0 before p100.
Yes, an unpatched CVE-2016-0248 can lead to sensitive data exposure, affecting the overall security posture of your organization.