The WebAdmin application 6.0.5, 6.0.8, and 7.0 before P2 in IBM Netezza, when SSL is not enabled, allows remote attackers to discover credentials by sniffing the network during the authentication process.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Netezza | Ibm | 6.0.5 (including) | 6.0.5 (including) |
Netezza | Ibm | 6.0.8 (including) | 6.0.8 (including) |
Netezza | Ibm | 7.0 (including) | 7.0 (including) |