PT-2006-3639 · Microsoft+1 · Sql Server+2
Robert Passlow
·
Published
2006-06-01
·
Updated
2018-10-18
·
CVE-2006-2719
CVSS v2.0
4.9
Medium
| Vector | AV:L/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
JIWA Financials version 6.4.14
Description
The issue allows context-dependent attackers to potentially obtain passwords because JIWA Financials stores usernames and passwords in cleartext in the HR Staff table in Microsoft SQL Server. It also sends these credentials in cleartext to the application's SQL Server ODBC driver.
Recommendations
For JIWA Financials version 6.4.14, consider implementing encryption for storing and transmitting usernames and passwords to prevent them from being obtained in cleartext. As a temporary workaround, restrict access to the HR Staff table and the SQL Server ODBC driver to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jiwa Financials
Sql Server
Odbc Driver For Sql Server