PT-2001-1591 · Akopia · Akopia Interchange
Published
2001-05-24
·
Updated
2017-12-19
·
CVE-2001-0372
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Akopia Interchange versions 4.5.3 through 4.6.3
Description
The issue allows a remote attacker to gain administrative access due to demo stores being installed with a default group account
:backup that has no password. This can be exploited via the demo stores, including (1) barry, (2) basic, or (3) construct.Recommendations
For versions 4.5.3 through 4.6.3, change the password of the
:backup group account to prevent unauthorized access. Consider removing or securing the demo stores (barry, basic, construct) until a proper fix is applied.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Akopia Interchange