First published: Tue May 29 2018(Updated: )
Affected versions of `ibm_db` insecurely download resources over HTTP. In scenarios where an attacker has a privileged network position, they can modify or read such resources at will. While the exact severity of impact for a vulnerability like this is highly variable and depends on the behavior of the package itself, it ranges from being able to read sensitive information all the way up to and including remote code execution. ## Recommendation Update to version 1.0.2 or later.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
npm/ibm_db | <1.0.2 | 1.0.2 |
IBM Db2 | <1.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-10577 varies based on network conditions and the attacker's capabilities, but it poses a serious risk due to potential unauthorized access to sensitive resources.
To fix CVE-2016-10577, update the ibm_db package to version 1.0.2 or later to ensure secure resource downloads over HTTPS.
CVE-2016-10577 affects all versions of ibm_db prior to 1.0.2.
CVE-2016-10577 can be exploited in scenarios where an attacker is in a privileged network position, allowing them to intercept or tamper with insecure HTTP resource downloads.
No, the ibm_db package is not deprecated, but its older versions prior to 1.0.2 have a significant vulnerability that requires updating to ensure security.