CVE-2016-2861
low
CVSS v3
3.7
CVSS v2
4.3
VIR risk
3.7
Description
IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3, 7.1.1 before 7.1.1.1, 8.5 before 8.5.0.3, and 8.6 before 8.6.0.8 does not properly encrypt data, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.
Predictions
Exploit likelihood
47%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21983036
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ibm | websphere_extreme_scale | 7.1.0 | |
| ibm | websphere_extreme_scale | 7.1.0.2 | |
| ibm | websphere_extreme_scale | 7.1.1 | |
| ibm | websphere_extreme_scale | 8.5.0 | |
| ibm | websphere_extreme_scale | 8.5.0.1 | |
| ibm | websphere_extreme_scale | 8.5.0.2 | |
| ibm | websphere_extreme_scale | 8.6.0 | |
| ibm | websphere_extreme_scale | 8.6.0.0 | |
| ibm | websphere_extreme_scale | 8.6.0.1 | |
| ibm | websphere_extreme_scale | 8.6.0.2 | |
| ibm | websphere_extreme_scale | 8.6.0.3 | |
| ibm | websphere_extreme_scale | 8.6.0.4 | |
| ibm | websphere_extreme_scale | 8.6.0.5 | |
| ibm | websphere_extreme_scale | 8.6.0.6 | |
| ibm | websphere_extreme_scale | 8.6.0.7 | |
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI60897
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI60898
- http://www-01.ibm.com/support/docview.wss?uid=swg21983036
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI60897
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI60898
- http://www-01.ibm.com/support/docview.wss?uid=swg21983036
CWEs
CWE-200
Verify integrity in audit chain (admin only). AS-IS.