CVE-2016-0238

low
Published 2017-07-05 · Modified 2026-05-13
CVSS v3
3.7
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v2
4.3
VIR risk
3.7

Description

IBM Security Guardium 9.0, 9.1, 9.5, 10.0, and 10.1 transmits sensitive data in cleartext in the query of the request. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 110409

Predictions

Exploit likelihood
47%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — https://exchange.xforce.ibmcloud.com/vulnerabilities/110409

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www.ibm.com/support/docview.wss?uid=swg21989124

Application impact

VendorProductVersionsFixed
ibmsecurity_guardium9.0
ibmsecurity_guardium9.1
ibmsecurity_guardium9.5
ibmsecurity_guardium10.0
ibmsecurity_guardium10.1
ibmsecurity_guardium10.1.2

References

CWEs

CWE-200

Verify integrity in audit chain (admin only). AS-IS.