SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-3431

The Teiid Java Database Connectivity (JDBC) socket, as used in JBoss Enterprise Data Services Platform before 5.3.0, does not encrypt login messages by default contrary to documentation and specification, which allows remote attackers to obtain login…

MEDIUM 4.3EPSS 1.76%

Does this matter?

Lower severity and a low EPSS score (1.76%). Track it; it rarely justifies an emergency change on its own.

Description

The Teiid Java Database Connectivity (JDBC) socket, as used in JBoss Enterprise Data Services Platform before 5.3.0, does not encrypt login messages by default contrary to documentation and specification, which allows remote attackers to obtain login credentials via a man-in-the-middle (MITM) attack.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
EPSS
1.76% probability · 77th percentile
CISA KEV
Not listed
Weakness
CWE-310
Affected
redhat/jboss enterprise data services platform
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.