PT-2008-5859 · Websense · Websense Enterprise

Published

2008-10-21

·

Updated

2011-03-08

·

CVE-2008-4646

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Websense Enterprise version 6.3.2
Description The issue concerns the storage of the SQL database system administrator password in plaintext within a log file, specifically CreateDbInstall.log, by the Websense Reporter Module. This allows local users to obtain the password and gain privileges to the database.
Recommendations For Websense Enterprise version 6.3.2, consider restricting access to the CreateDbInstall.log file to prevent unauthorized users from obtaining the database administrator password. Additionally, as a temporary workaround, manually encrypt or securely store the SQL database system administrator password until a more permanent solution is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-4646

Affected Products

Websense Enterprise