CVE Published: 01/05/2012 |
CVE Updated: 06/08/2024 |
CVE Year: 2012 Source: ibm |
Vendor: n/a |
Product: n/a Status : PUBLISHED
CVE-2012-2162 Description
The Web Server Plug-in in IBM WebSphere Application Server (WAS) 8.0 and earlier uses unencrypted HTTP communication after expiration of the plugin-key.kdb password, which allows remote attackers to obtain sensitive information by sniffing the network, or spoof arbitrary servers via a man-in-the-middle attack.