PT-2019-18121 · Teradata · Teradata Viewpoint
Published
2019-01-21
·
Updated
2019-02-07
·
CVE-2019-6499
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Teradata Viewpoint versions prior to 14.0
Teradata Viewpoint version 16.20.00.02-b80 and earlier
Description
The issue concerns a hardcoded password
TDv1i2e3w4 for the viewpoint database account, which could be exploited by malicious users to compromise the system. This password is found in the server.xml file located in the viewpoint-portalconf directory.Recommendations
For Teradata Viewpoint versions prior to 14.0, update to version 14.0 or later.
For Teradata Viewpoint version 16.20.00.02-b80 and earlier, update to a version later than 16.20.00.02-b80.
As a temporary workaround, consider changing the hardcoded password
TDv1i2e3w4 for the viewpoint database account to a secure password until a patch is available.Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Teradata Viewpoint