IBM Security Guardium 9.0, 9.1, 9.5, 10.0, and 10.1 transmits sensitive data in cleartext in the query of the request. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 110409
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0238
Reference (s):
- BID:99379
- URL: http://www.securityfocus.com/bid/99379
- http://www.ibm.com/support/docview.wss?uid=swg21989124
- https://exchange.xforce.ibmcloud.com/vulnerabilities/110409