PT-2011-4582 · Netsaro · Netsaro Enterprise Messenger Server
Publicado
2011-09-27
·
Atualizado
2012-05-21
·
CVE-2011-3692
CVSS v2.0
1.9
Baixa
| Vetor | AV:L/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
NetSaro Enterprise Messenger Server version 2.0
Description
The issue allows local users to obtain sensitive information by reading the configuration.xml file, which stores cleartext console credentials, and then performing a base64 decoding step.
Recommendations
For NetSaro Enterprise Messenger Server version 2.0, consider encrypting or securely storing console credentials in the configuration.xml file to prevent unauthorized access. As a temporary workaround, restrict access to the configuration.xml file to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Netsaro Enterprise Messenger Server