PT-2014-2926 · Oracle+1 · Jd Edwards Enterpriseone+1

Publicado

2014-08-12

·

Atualizado

2017-08-29

·

CVE-2013-5433

CVSS v2.0

4.0

Média

VetorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM InfoSphere Optim versions 3.0 through 9.1
Description The issue concerns hardcoded database credentials in the Data Growth Solution for JD Edwards EnterpriseOne. This allows remote authenticated users to obtain sensitive information by reading an unspecified field in an XML document.
Recommendations For versions 3.0 through 9.1, update the configuration to remove hardcoded database credentials and instead use secure authentication methods. As a temporary workaround, consider restricting access to the XML documents that contain the sensitive information.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-5433

Produtos afetados

Ibm Infosphere Optim
Jd Edwards Enterpriseone