CVE Vulnerabilities

CVE-2016-2953

Published: Nov 30, 2016 | Modified: Nov 30, 2016
CVSS 3.x
3.7
LOW
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 does not require SSL, which allows remote attackers to obtain sensitive cleartext information by sniffing the network.

Affected Software

Name Vendor Start Version End Version
Connections Ibm 4.5.0.0 4.5.0.0
Connections Ibm 5.0.0.0 5.0.0.0
Connections Ibm 4.0.0.0 4.0.0.0

References