Cleartext transmission of sensitive information in Apache MINA - CVE-2019-0231
Published: March 19, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to incorrect handling of close_notify SSL/TLS messages that results in software not closing the connection and retaining the socket opened, which allows a client to receive clear text messages afterward. A remote attacker can intercept traffic between client and server application and gain access to potentially sensitive information.
Affected software
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Zimbra Collaboration
IBM Common Licensing
Oracle Access Manager
IBM Cognos Analytics
How to mitigate CVE-2019-0231
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.7.0
Zimbra Collaboration - addressed in versions 8.8.15 Patch 32, 9.0.0 Patch 25
IBM Common Licensing - update to 9.0.0.2
IBM Cognos Analytics - addressed in versions 11.2.4 FP4, 12.0.3 IF1