CVE-2016-2953
low
CVSS v3
3.7
CVSS v2
4.3
VIR risk
3.7
Description
IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 does not require SSL, which allows remote attackers to obtain sensitive cleartext information by sniffing the network.
Predictions
Exploit likelihood
47%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21990888
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ibm | connections | 4.0.0.0 | |
| ibm | connections | 4.5.0.0 | |
| ibm | connections | 5.0.0.0 | |
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1LO90268
- http://www-01.ibm.com/support/docview.wss?uid=swg1LO90295
- http://www-01.ibm.com/support/docview.wss?uid=swg21990888
- http://www.securityfocus.com/bid/94415
- http://www-01.ibm.com/support/docview.wss?uid=swg1LO90268
- http://www-01.ibm.com/support/docview.wss?uid=swg1LO90295
- http://www-01.ibm.com/support/docview.wss?uid=swg21990888
- http://www.securityfocus.com/bid/94415
CWEs
CWE-310
Verify integrity in audit chain (admin only). AS-IS.