Lawson Financials 8.0, when configured to use a third party relational database, stores usernames and passwords in a world-readable file, which allows local users to read the passwords and log onto the database.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://seclists.org/lists/bugtraq/2002/Dec/0012.html | mailing list |
http://www.securityfocus.com/bid/6293 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/10742 | vdb entry |