PT-2018-4226 · Thycotic · Thycotic Secret Server

Published

2018-03-09

·

Updated

2018-03-29

·

CVE-2014-4861

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Thycotic Secret Server versions prior to 8.6.000010
Description The issue arises from the Remote Desktop Launcher in Thycotic Secret Server, which fails to properly clean up a temporary file containing an encrypted password after a session has ended.
Recommendations For versions prior to 8.6.000010, update to version 8.6.000010 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-4861

Affected Products

Thycotic Secret Server