Security Advisory

CVE-2012-2162

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2012-05-01 19:00:00
Last updated 2024-08-06 19:26:08
Assigner ibm
CVSS score not scored
State PUBLISHED

Description

The Web Server Plug-in in IBM WebSphere Application Server (WAS) 8.0 and earlier uses unencrypted HTTP communication after expiration of the plugin-key.kdb password, which allows remote attackers to obtain sensitive information by sniffing the network, or spoof arbitrary servers via a man-in-the-middle attack.