PT-2006-3639 · Microsoft+1 · Sql Server+2

Robert Passlow

·

Published

2006-06-01

·

Updated

2018-10-18

·

CVE-2006-2719

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions JIWA Financials version 6.4.14
Description The issue allows context-dependent attackers to potentially obtain passwords because JIWA Financials stores usernames and passwords in cleartext in the HR Staff table in Microsoft SQL Server. It also sends these credentials in cleartext to the application's SQL Server ODBC driver.
Recommendations For JIWA Financials version 6.4.14, consider implementing encryption for storing and transmitting usernames and passwords to prevent them from being obtained in cleartext. As a temporary workaround, restrict access to the HR Staff table and the SQL Server ODBC driver to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2719

Affected Products

Jiwa Financials
Sql Server
Odbc Driver For Sql Server