PT-2002-1090 · Compaq+2 · Compaq Insight Manager+5

Publicado

2002-08-12

·

Atualizado

2018-08-13

·

CVE-2000-1209

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft SQL Server 2000 SQL Server 7.0 Data Engine (MSDE) 1.0 Tumbleweed Secure Mail (MMS) Compaq Insight Manager Visio 2000
Description The issue allows remote attackers to gain privileges due to the default null password of the sa account. This has been exploited by worms such as Voyager Alpha Force and Spida.
Recommendations For Microsoft SQL Server 2000, update the sa account password to a secure value. For SQL Server 7.0, change the default sa account password. For Data Engine (MSDE) 1.0, modify the sa account to use a non-null password. For Tumbleweed Secure Mail (MMS), Compaq Insight Manager, and Visio 2000, ensure that the underlying SQL server components have secure sa account passwords configured.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2000-1209

Produtos afetados

Compaq Insight Manager
Data Engine (Msde) 1.0
Sql Server 2000
Sql Server 7.0
Tumbleweed Secure Mail
Visio 2000