CVE-2012-2173
IBM Security AppScan Source 7.x-8.x - Password Hash Exposure via ODBC Driver
Title source: llmDescription
The ODBC driver in IBM Security AppScan Source 7.x and 8.x before 8.6 sends an SHA-1 hash of the connection password during connections to a solidDB database, which allows remote attackers to obtain sensitive information by sniffing the network.
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/75242
Various Sources x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=swg21598423
Scores
EPSS
0.0117
EPSS Percentile
64.2%
Details
CWE
CWE-255
Status
published
Products (6)
ibm/security_appscan_source
7.0
ibm/security_appscan_source
8.0
ibm/security_appscan_source
8.0.0.1
ibm/security_appscan_source
8.0.0.2
ibm/security_appscan_source
8.5
ibm/security_appscan_source
8.5.0.1
Published
Jun 20, 2012
Tracked Since
Feb 18, 2026