PT-2014-3204 · Opentext · Opentext Exceed Ondemand

Publicado

2014-05-19

·

Atualizado

2014-05-19

·

CVE-2013-6805

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenText Exceed OnDemand (EoD) version 8
Description The issue concerns the use of weak encryption for passwords, making it easier for remote attackers to discover credentials by sniffing the network or for local users to discover credentials by reading a .eod8 file.
Recommendations For OpenText Exceed OnDemand (EoD) version 8, consider implementing stronger encryption methods for password storage to mitigate the risk of credential discovery. As a temporary workaround, restrict access to .eod8 files and limit network sniffing capabilities to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-6805

Produtos afetados

Opentext Exceed Ondemand