CVE-2016-0248: Infoleak
Published Sep 26, 2016
·Updated
IBM Security Guardium 9.0 before p700 and 10.0 before p100 allows man-in-the-middle attackers to obtain sensitive query-string information from SSL sessions via unspecified vectors.
Affected Software
2 affected components
IBM Security Guardium=9.0
IBM Security Guardium=10.0
Remediation
Patch Available
Event History
Sep 26, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-0248?
CVE-2016-0248 has a medium severity rating due to its potential to allow man-in-the-middle attacks.
2
How do I fix CVE-2016-0248?
To fix CVE-2016-0248, upgrade IBM Security Guardium to version 9.0 p700 or 10.0 p100 or later.
3
What types of attacks does CVE-2016-0248 allow?
CVE-2016-0248 allows man-in-the-middle attackers to capture sensitive query-string information from SSL sessions.
4
What versions of IBM Security Guardium are affected by CVE-2016-0248?
CVE-2016-0248 affects IBM Security Guardium versions 9.0 before p700 and 10.0 before p100.
5
Can an unpatched CVE-2016-0248 impact my organization?
Yes, an unpatched CVE-2016-0248 can lead to sensitive data exposure, affecting the overall security posture of your organization.