VYPR
Low severity3.7NVD Advisory· Published Sep 26, 2016· Updated May 6, 2026

CVE-2016-0248

CVE-2016-0248

Description

IBM Security Guardium transmits query parameters in SSL requests, allowing MITM attackers to intercept sensitive data.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM Security Guardium transmits query parameters in SSL requests, allowing MITM attackers to intercept sensitive data.

Vulnerability

The vulnerability exists in IBM Security Guardium versions 9.0 before p700 and 10.0 before p100. It transmits query parameters in SSL requests without proper protection, enabling man-in-the-middle attackers to capture sensitive information from SSL sessions via unspecified vectors [1].

Exploitation

An attacker with network access to the communication path between the Guardium client and server can perform a man-in-the-middle attack. No authentication is required, but the attacker must be able to intercept and decrypt SSL traffic (e.g., by using a rogue certificate or exploiting weak cipher suites). The exact exploitation steps are not detailed, but the attack leverages the transmission of query parameters in plaintext within the SSL session [1].

Impact

Successful exploitation allows the attacker to obtain sensitive query-string information, leading to limited confidentiality impact (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N). The attacker gains no write or execution capabilities; only disclosure of data passed in query strings [1].

Mitigation

IBM released fixes: p700 for version 9.0 and p100 for version 10.0. Users should upgrade to these or later versions. No workarounds are available. The vulnerability is not listed on CISA's KEV [1].

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3
  • cpe:2.3:a:ibm:security_guardium:10.0:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:ibm:security_guardium:10.0:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:security_guardium:9.0:*:*:*:*:*:*:*
    • (no CPE)range: 9.0 before p700, 10.0 before p100

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.