PT-2011-1349 · Pentaho · Pentaho Bi Server

Published

2011-09-13

·

Updated

2018-10-10

·

CVE-2009-5100

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Pentaho BI Server versions 1.7.0.1062 and earlier
Description The issue allows physically proximate attackers to potentially obtain the password because the autocomplete tag is not set to off on web pages that use a password field.
Recommendations For Pentaho BI Server versions 1.7.0.1062 and earlier, set the autocomplete tag to off on all web pages that contain password fields to prevent potential password exposure.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-5100

Affected Products

Pentaho Bi Server