Citrix EdgeSight 4.2 and 4.5 for Presentation Server, EdgeSight 4.2 and 4.5 for Endpoints, and EdgeSight for NetScaler 1.0 and 1.1 do not properly store database credentials in configuration files, which allows local users to obtain sensitive information.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://support.citrix.com/article/CTX115281 | patch |
https://exchange.xforce.ibmcloud.com/vulnerabilities/38861 | vdb entry |
http://www.vupen.com/english/advisories/2007/4091 | vdb entry |
http://www.securitytracker.com/id?1019050 | vdb entry |
http://www.securityfocus.com/bid/26705 | patch vdb entry exploit |
http://secunia.com/advisories/27935 | third party advisory vendor advisory |