The Websense Reporter Module in Websense Enterprise 6.3.2 stores the SQL database system administrator password in plaintext in CreateDbInstall.log, which allows local users to gain privileges to the database.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://www.zebux.org/pub/Advisory/Advisory_Websense_Reporter_Password_Disclosure_200810.txt | |
http://secunia.com/advisories/32264 | third party advisory vendor advisory |
http://www.securitytracker.com/id?1021058 | vdb entry |
http://www.vupen.com/english/advisories/2008/2819 | vdb entry |
http://www.securityfocus.com/bid/31746 | vdb entry |