PT-2011-4582 · Netsaro · Netsaro Enterprise Messenger Server
Published
2011-09-27
·
Updated
2012-05-21
·
CVE-2011-3692
CVSS v2.0
1.9
Low
| Vector | AV:L/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
NetSaro Enterprise Messenger Server version 2.0
Description
The issue allows local users to obtain sensitive information by reading the configuration.xml file, which stores cleartext console credentials, and then performing a base64 decoding step.
Recommendations
For NetSaro Enterprise Messenger Server version 2.0, consider encrypting or securely storing console credentials in the configuration.xml file to prevent unauthorized access. As a temporary workaround, restrict access to the configuration.xml file to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netsaro Enterprise Messenger Server