PT-2008-5859 · Websense · Websense Enterprise
Publicado
2008-10-21
·
Atualizado
2011-03-08
·
CVE-2008-4646
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Websense Enterprise version 6.3.2
Description
The issue concerns the storage of the SQL database system administrator password in plaintext within a log file, specifically CreateDbInstall.log, by the Websense Reporter Module. This allows local users to obtain the password and gain privileges to the database.
Recommendations
For Websense Enterprise version 6.3.2, consider restricting access to the CreateDbInstall.log file to prevent unauthorized users from obtaining the database administrator password. Additionally, as a temporary workaround, manually encrypt or securely store the SQL database system administrator password until a more permanent solution is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Websense Enterprise