The login component in SOAP Gateway in IBM IMS Enterprise Suite 1.1, 2.1, and 2.2 uses cleartext credentials, which allows remote attackers to obtain sensitive information by sniffing the network.
2013-04-05T16:55:01.627
2025-04-11T00:51:21.963
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | ims_enterprise_suite | 1.1 | Yes |
Application | ibm | ims_enterprise_suite | 2.1 | Yes |
Application | ibm | ims_enterprise_suite | 2.2 | Yes |