The datasource definition editor in IBM InfoSphere Guardium 8.2 and earlier, when the save-password setting is enabled, transmits cleartext database credentials, which allows remote attackers to obtain sensitive information by sniffing the network.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Infosphere_guardium | Ibm | * | 8.2 (including) |
Infosphere_guardium | Ibm | 8.00 (including) | 8.00 (including) |
Infosphere_guardium | Ibm | 8.01 (including) | 8.01 (including) |