IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 does not require SSL, which allows remote attackers to obtain sensitive cleartext information by sniffing the network.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-4026 | IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 does not require SSL, which allows remote attackers to obtain sensitive cleartext information by sniffing the network. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2024-08-05T23:40:13.825Z
Reserved: 2016-03-09T00:00:00
Link: CVE-2016-2953
No data.
Status : Deferred
Published: 2016-11-30T11:59:16.403
Modified: 2025-04-12T10:46:40.837
Link: CVE-2016-2953
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD