First published: Tue May 17 2016(Updated: )
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.41, 8.0 before 8.0.0.13, and 8.5 before 8.5.5.10, when FIPS 140-2 is enabled, misconfigures TLS, which allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.2 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.3 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.4 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.5 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.7 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.9 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.11 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.13 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.15 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.17 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.19 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.21 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.23 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.25 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.27 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.29 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.31 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.33 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.35 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.37 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.39 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.2 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.3 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.4 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.5 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.6 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.7 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.8 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.9 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.10 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.11 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.12 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.0.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.0.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.0.2 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.2 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.3 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.4 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.5 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.6 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.7 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.8 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-0306 is rated as high due to its potential to allow man-in-the-middle attacks and the compromise of sensitive information.
To fix CVE-2016-0306, upgrade your IBM WebSphere Application Server to a version that is not vulnerable, specifically 7.0.0.41, 8.0.0.13, or 8.5.5.10 or later.
Affected versions of IBM WebSphere Application Server include 7.0 prior to 7.0.0.41, 8.0 prior to 8.0.0.13, and 8.5 prior to 8.5.5.10.
CVE-2016-0306 can facilitate man-in-the-middle attacks, allowing attackers to intercept and potentially alter communications.
Yes, CVE-2016-0306 specifically arises when FIPS 140-2 is enabled, leading to misconfiguration of TLS.