PT-2011-4582 · Netsaro · Netsaro Enterprise Messenger Server

Publicado

2011-09-27

·

Atualizado

2012-05-21

·

CVE-2011-3692

CVSS v2.0

1.9

Baixa

VetorAV:L/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions NetSaro Enterprise Messenger Server version 2.0
Description The issue allows local users to obtain sensitive information by reading the configuration.xml file, which stores cleartext console credentials, and then performing a base64 decoding step.
Recommendations For NetSaro Enterprise Messenger Server version 2.0, consider encrypting or securely storing console credentials in the configuration.xml file to prevent unauthorized access. As a temporary workaround, restrict access to the configuration.xml file to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-3692

Produtos afetados

Netsaro Enterprise Messenger Server