CVE-2016-0248
low
CVSS v3
3.7
CVSS v2
4.3
VIR risk
3.7
Description
IBM Security Guardium 9.0 before p700 and 10.0 before p100 allows man-in-the-middle attackers to obtain sensitive query-string information from SSL sessions via unspecified vectors.
Predictions
Exploit likelihood
47%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21982031
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ibm | security_guardium | 9.0 | |
| ibm | security_guardium | 10.0 | |
References
CWEs
CWE-200
Verify integrity in audit chain (admin only). AS-IS.