PT-2014-3204 · Opentext · Opentext Exceed Ondemand
Published
2014-05-19
·
Updated
2014-05-19
·
CVE-2013-6805
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenText Exceed OnDemand (EoD) version 8
Description
The issue concerns the use of weak encryption for passwords, making it easier for remote attackers to discover credentials by sniffing the network or for local users to discover credentials by reading a .eod8 file.
Recommendations
For OpenText Exceed OnDemand (EoD) version 8, consider implementing stronger encryption methods for password storage to mitigate the risk of credential discovery. As a temporary workaround, restrict access to .eod8 files and limit network sniffing capabilities to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opentext Exceed Ondemand