« Volver al listado

CVE-2012-2173

Estado: ModificadaMedia (5)—

The ODBC driver in IBM Security AppScan Source 7.x and 8.x before 8.6 sends an SHA-1 hash of the connection password during connections to a solidDB database, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-2173",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@us.ibm.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-06-20T10:27:28.317",
  "references": [
    {
      "url": "http://www.ibm.com/support/docview.wss?uid=swg21598423",
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/75242",
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "http://www.ibm.com/support/docview.wss?uid=swg21598423",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/75242",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-255"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The ODBC driver in IBM Security AppScan Source 7.x and 8.x before 8.6 sends an SHA-1 hash of the connection password during connections to a solidDB database, which allows remote attackers to obtain sensitive information by sniffing the network."
    },
    {
      "lang": "es",
      "value": "El controlador ODBC de IBM Security AppScan Source v7.x y v8.x anterior a v8.6 envía un hash SHA-1 de la contraseña de conexión durante las conexiones a una base de datos solidDB, que permite a atacantes remotos obtener información sensible el tráfico de la red."
    }
  ],
  "lastModified": "2026-06-16T23:41:07.817",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ibm:security_appscan_source:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E2A8F522-B785-4C9D-B133-D895B8A5D0E2"
            },
            {
              "criteria": "cpe:2.3:a:ibm:security_appscan_source:8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C3EC310D-7C7F-4B5A-AFFC-58A38B67A0CA"
            },
            {
              "criteria": "cpe:2.3:a:ibm:security_appscan_source:8.0.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "66B37DEF-109F-4769-901C-DD8B33DEA054"
            },
            {
              "criteria": "cpe:2.3:a:ibm:security_appscan_source:8.0.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3FA1883D-1576-43B9-904A-536C0C249112"
            },
            {
              "criteria": "cpe:2.3:a:ibm:security_appscan_source:8.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6990B7A5-3C72-494B-A512-23E508B71CE4"
            },
            {
              "criteria": "cpe:2.3:a:ibm:security_appscan_source:8.5.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FBE84BDC-3AC4-4BD2-9BF8-3C6C5E1DCF56"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@us.ibm.com"
}