PT-2011-1349 · Pentaho · Pentaho Bi Server
Published
2011-09-13
·
Updated
2018-10-10
·
CVE-2009-5100
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Pentaho BI Server versions 1.7.0.1062 and earlier
Description
The issue allows physically proximate attackers to potentially obtain the password because the autocomplete tag is not set to off on web pages that use a password field.
Recommendations
For Pentaho BI Server versions 1.7.0.1062 and earlier, set the autocomplete tag to off on all web pages that contain password fields to prevent potential password exposure.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pentaho Bi Server