Vulnerability Name: | CVE-2015-4961 (CCN-105513) | ||||||||||||
Assigned: | 2015-06-24 | ||||||||||||
Published: | 2016-09-12 | ||||||||||||
Updated: | 2016-12-22 | ||||||||||||
Summary: | IBM Tealeaf Customer Experience 8.x before 8.7.1.8847 FP10, 8.8.x before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108 FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224 FP3 does not encrypt connections between internal servers, which allows remote attackers to obtain sensitive information by sniffing the network for HTTP traffic. | ||||||||||||
CVSS v3 Severity: | 2.6 Low (CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N) 2.3 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
2.7 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 2.9 Low (CVSS v2 Vector: AV:A/AC:M/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2015-4961 Source: CONFIRM Type: Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21965077 Source: CCN Type: IBM Security Bulletin 1965077 (Tealeaf Customer Experience) IBM Tealeaf Customer Experience internal connections not encrypted (CVE-2015-4961) Source: BID Type: UNKNOWN 94976 Source: CCN Type: BID-94976 IBM Tealeaf Customer Experience CVE-2015-4961 Information Disclosure Vulnerability Source: XF Type: UNKNOWN ibm-tealeaf-cve20154961-info-disc(105513) | ||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
BACK |