CVE-2012-5756
Published Nov 23, 2012
Last updated 7 years ago
Overview
- Description
- The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2, when a collective configuration is enabled, has a single secret key that is shared across different customers' installations, which allows remote attackers to spoof a container server by (1) sniffing the network to locate a cleartext transmission of this key or (2) leveraging knowledge of this key from another installation.
- Source
- psirt@us.ibm.com
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-310
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:ibm:websphere_datapower_xc10_appliance:2.0.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C430DE33-2AEE-414D-BA99-3E363798005C" }, { "criteria": "cpe:2.3:h:ibm:websphere_datapower_xc10_appliance:2.0.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "66CF002D-2EF9-4C77-B9B5-063A33113AF3" }, { "criteria": "cpe:2.3:h:ibm:websphere_datapower_xc10_appliance:2.0.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D733550C-4C9B-4AE0-8865-9761D6556ED6" }, { "criteria": "cpe:2.3:h:ibm:websphere_datapower_xc10_appliance:2.0.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8188D330-B466-47A1-B4C6-113A070A98A2" }, { "criteria": "cpe:2.3:h:ibm:websphere_datapower_xc10_appliance:2.1.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B91BAA10-2047-43D3-A2CF-7FA541E6DA43" }, { "criteria": "cpe:2.3:h:ibm:websphere_datapower_xc10_appliance:2.1.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B3327710-8E4F-4D38-AD50-BB95669C7B09" }, { "criteria": "cpe:2.3:h:ibm:websphere_datapower_xc10_appliance:2.1.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BDA3ECF3-DC6F-4DD3-B179-B02C637ADAE7" } ], "operator": "OR" } ] } ]