PT-2019-18121 · Teradata · Teradata Viewpoint

Published

2019-01-21

·

Updated

2019-02-07

·

CVE-2019-6499

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Teradata Viewpoint versions prior to 14.0 Teradata Viewpoint version 16.20.00.02-b80 and earlier
Description The issue concerns a hardcoded password TDv1i2e3w4 for the viewpoint database account, which could be exploited by malicious users to compromise the system. This password is found in the server.xml file located in the viewpoint-portalconf directory.
Recommendations For Teradata Viewpoint versions prior to 14.0, update to version 14.0 or later. For Teradata Viewpoint version 16.20.00.02-b80 and earlier, update to a version later than 16.20.00.02-b80. As a temporary workaround, consider changing the hardcoded password TDv1i2e3w4 for the viewpoint database account to a secure password until a patch is available.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-6499

Affected Products

Teradata Viewpoint