CVE-2012-2173

The ODBC driver in IBM Security AppScan Source 7.x and 8.x before 8.6 sends an SHA-1 hash of the connection password during connections to a solidDB database, which allows remote attackers to obtain sensitive information by sniffing the network.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
ibmCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 45%
VendorProductVersion
ibmsecurity_appscan_source
7.0
ibmsecurity_appscan_source
8.0
ibmsecurity_appscan_source
8.0.0.1
ibmsecurity_appscan_source
8.0.0.2
ibmsecurity_appscan_source
8.5
ibmsecurity_appscan_source
8.5.0.1
𝑥
= Vulnerable software versions
Common Weakness Enumeration