Junglewise Threat Intelligence

CVE-2016-10577: IBM ibm_db insecure HTTP resource download

CVE-2016-10577 · Severity: low · CVSS 3 · Published 2019-02-18

Vendors: npm, IBM.

Executive brief

IBM's ibm_db is a Node.js database driver that insecurely downloads resources over unencrypted HTTP connections. An attacker positioned on the network path can intercept and modify these downloads, potentially injecting malicious code or stealing sensitive data, leading to remote code execution or data exposure depending on what resources are downloaded.

Technical details

The vulnerability is a cleartext protocol flaw (CWE-311) where ibm_db downloads critical resources over HTTP instead of HTTPS. This occurs during package installation or runtime operation. An attacker with network-level access (man-in-the-middle position) can intercept these HTTP requests and serve malicious content, achieving remote code execution or information disclosure. No authentication or user interaction is required beyond initiating the download. The issue was patched in version 1.0.2 and later.

Affected products

  • IBM ibm_db before 1.0.2

Timeline

  • 2019-02-18: disclosed
  • 2016: patched: Fix version 1.0.2 available

References

Related threats