CVE-2016-0248
published 2016-09-26CVE-2016-0248: IBM Security Guardium 9.0 before p700 and 10.0 before p100 allows man-in-the-middle attackers to obtain sensitive query-string information from SSL sessions…
PriorityP411low3.7CVSS 3.0
AVNACHPRNUINSUCLINAN
EPSS
0.77%
51.2th percentile
IBM Security Guardium 9.0 before p700 and 10.0 before p100 allows man-in-the-middle attackers to obtain sensitive query-string information from SSL sessions via unspecified vectors.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | security_guardium | — | — |
| ibm | security_guardium | — | — |
CVSS provenance
nvdv3.03.7LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-6344 JBoss bpms 6.3.x cookie does not set httponly
bugzilla·2016-08-31·CVSS 5.3
CVE-2016-6344 [MEDIUM] CVE-2016-6344 JBoss bpms 6.3.x cookie does not set httponly
CVE-2016-6344 JBoss bpms 6.3.x cookie does not set httponly
Cookies including JSESSIONID does not set httponly, so attackers may be able to access information which needs authentication using them.
Discussion:
Acknowledgments:
Name: Jeremy Choi (Red Hat Product Security Team)
---
This issue has been addressed in the following products:
Red Hat JBoss BPM Suite 6.4.1
Via RHSA-2017:0249 https://rhn.redhat.com/errata/RHSA-2017-0249.html
---
This issue has been addressed in the following products:
Red Hat JBoss BRMS 6.4.1
Via RHSA-2017:0248 https://rhn.redhat.com/errata/RHSA-2017-0248.html
Bugzilla
CVE-2016-4434 tika: XML External Entity vulnerability
bugzilla·2016-05-27·CVSS 7.8
CVE-2016-4434 [HIGH] CVE-2016-4434 tika: XML External Entity vulnerability
CVE-2016-4434 tika: XML External Entity vulnerability
Apache Tika parses XML within numerous file formats. In some instances, such as spreadsheets in OOXML files, XMP in PDF, and other file formats, the initialization of the XML parser or the choice of handlers did not protect against XML External Entity (XXE) vulnerabilities.
References:
http://seclists.org/oss-sec/2016/q2/413
Discussion:
Created tika tracking bugs for this issue:
Affects: fedora-all [bug 1340387]
---
This issue has been addressed in the following products:
Red Hat JBoss BPM Suite 6.4.1
Via RHSA-2017:0249 https://rhn.redhat.com/errata/RHSA-2017-0249.html
---
This issue has been addressed in the following products:
Red Hat JBoss BRMS 6.4.1
Via RHSA-2017:0248 https://rhn.redhat.com/errata/RHSA-2017-0248.html
2016-09-26
Published