PT-2019-18121 · Teradata · Teradata Viewpoint
Publicado
2019-01-21
·
Atualizado
2019-02-07
·
CVE-2019-6499
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Teradata Viewpoint versions prior to 14.0
Teradata Viewpoint version 16.20.00.02-b80 and earlier
Description
The issue concerns a hardcoded password
TDv1i2e3w4 for the viewpoint database account, which could be exploited by malicious users to compromise the system. This password is found in the server.xml file located in the viewpoint-portalconf directory.Recommendations
For Teradata Viewpoint versions prior to 14.0, update to version 14.0 or later.
For Teradata Viewpoint version 16.20.00.02-b80 and earlier, update to a version later than 16.20.00.02-b80.
As a temporary workaround, consider changing the hardcoded password
TDv1i2e3w4 for the viewpoint database account to a secure password until a patch is available.Correção
Using Hardcoded Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Teradata Viewpoint