Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:ibm:security_appscan_source:7.0:*:*:*:*:*:*:*", "matchCriteriaId": "E2A8F522-B785-4C9D-B133-D895B8A5D0E2", "vulnerable": true}, {"criteria": "cpe:2.3:a:ibm:security_appscan_source:8.0:*:*:*:*:*:*:*", "matchCriteriaId": "C3EC310D-7C7F-4B5A-AFFC-58A38B67A0CA", "vulnerable": true}, {"criteria": "cpe:2.3:a:ibm:security_appscan_source:8.0.0.1:*:*:*:*:*:*:*", "matchCriteriaId": "66B37DEF-109F-4769-901C-DD8B33DEA054", "vulnerable": true}, {"criteria": "cpe:2.3:a:ibm:security_appscan_source:8.0.0.2:*:*:*:*:*:*:*", "matchCriteriaId": "3FA1883D-1576-43B9-904A-536C0C249112", "vulnerable": true}, {"criteria": "cpe:2.3:a:ibm:security_appscan_source:8.5:*:*:*:*:*:*:*", "matchCriteriaId": "6990B7A5-3C72-494B-A512-23E508B71CE4", "vulnerable": true}, {"criteria": "cpe:2.3:a:ibm:security_appscan_source:8.5.0.1:*:*:*:*:*:*:*", "matchCriteriaId": "FBE84BDC-3AC4-4BD2-9BF8-3C6C5E1DCF56", "vulnerable": true}], "negate": false, "operator": "OR"}]}], "cveTags": [], "descriptions": [{"lang": "en", "value": "The ODBC driver in IBM Security AppScan Source 7.x and 8.x before 8.6 sends an SHA-1 hash of the connection password during connections to a solidDB database, which allows remote attackers to obtain sensitive information by sniffing the network."}, {"lang": "es", "value": "El controlador ODBC de IBM Security AppScan Source v7.x y v8.x anterior a v8.6 env\u00eda un hash SHA-1 de la contrase\u00f1a de conexi\u00f3n durante las conexiones a una base de datos solidDB, que permite a atacantes remotos obtener informaci\u00f3n sensible el tr\u00e1fico de la red."}], "id": "CVE-2012-2173", "lastModified": "2025-04-11T00:51:21.963", "metrics": {"cvssMetricV2": [{"acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": {"accessComplexity": "LOW", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 5.0, "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N", "version": "2.0"}, "exploitabilityScore": 10.0, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false}]}, "published": "2012-06-20T10:27:28.317", "references": [{"source": "psirt@us.ibm.com", "url": "http://www.ibm.com/support/docview.wss?uid=swg21598423"}, {"source": "psirt@us.ibm.com", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/75242"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.ibm.com/support/docview.wss?uid=swg21598423"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/75242"}], "sourceIdentifier": "psirt@us.ibm.com", "vulnStatus": "Deferred", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-255"}], "source": "nvd@nist.gov", "type": "Primary"}]}