PT-2014-2926 · Oracle+1 · Jd Edwards Enterpriseone+1

Published

2014-08-12

·

Updated

2017-08-29

·

CVE-2013-5433

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM InfoSphere Optim versions 3.0 through 9.1
Description The issue concerns hardcoded database credentials in the Data Growth Solution for JD Edwards EnterpriseOne. This allows remote authenticated users to obtain sensitive information by reading an unspecified field in an XML document.
Recommendations For versions 3.0 through 9.1, update the configuration to remove hardcoded database credentials and instead use secure authentication methods. As a temporary workaround, consider restricting access to the XML documents that contain the sensitive information.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-5433

Affected Products

Ibm Infosphere Optim
Jd Edwards Enterpriseone