Boletines de Vulnerabilidades

IBM Security Bulletin: Vulnerability in IBM InfoSphere Guardium Database Activity Monitoring (CVE-2010-3312)


Información sobre el sistema

   
Software afectado IBM

Descripción

The datasource definition editor in IBM® InfoSphere® Guardiumâ„¢ v8.0 and v8.2, when the save-password setting is enabled, transmits cleartext database credentials, which allows remote attackers to obtain sensitive information by sniffing the network. CVE(s): CVE-2012-3312 Affected product(s) and affected version(s): Versions 8.0 and 8.2 of IBM InfoSphere Guardium Database Activity Monitoring are affected. Refer to the following reference URLs for remediation and

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerability_in_ibm_infosphere_guardium_database_activity_monitoring_cve_2010_3312?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2012-3312 ,CVE-2010-3312 ,CVE-2013-4353 ,CVE-2013-6450 ,CVE-2013-6449 ,CVE-2013-4057 ,CVE-2013-4058 ,CVE-2013-4059 ,CVE-2014-0848 ,CVE-2013-4066 and CVE-2013-4067.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2014-03-17

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT