Boletines de Vulnerabilidades

IBM Security Bulletin: Vulnerability in IBM InfoSphere Guardium Database Activity Monitoring (CVE-2010-3312)

   
Software afectado IBM
 
The datasource definition editor in IBM® InfoSphere® Guardiumâ„¢ v8.0 and v8.2, when the save-password setting is enabled, transmits cleartext database credentials, which allows remote attackers to obtain sensitive information by sniffing the network. CVE(s): CVE-2012-3312 Affected product(s) and affected version(s): Versions 8.0 and 8.2 of IBM InfoSphere Guardium Database Activity Monitoring are affected. Refer to the following reference URLs for remediation and

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerability_in_ibm_infosphere_guardium_database_activity_monitoring_cve_2010_3312?lang=en_us