Application Access Server (A-A-S) 2.0.48 stores (1) passwords and (2) the port keyword in cleartext in aas.ini, which allows local users to obtain sensitive information by reading this file.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Link | Tags |
---|---|
http://www.syhunt.com/advisories/?id=aas-multiple | broken link |
http://www.securityfocus.com/archive/1/503434/100/0/threaded | mailing list vdb entry third party advisory broken link |
http://www.securityfocus.com/bid/34911 | vdb entry third party advisory broken link |
https://exchange.xforce.ibmcloud.com/vulnerabilities/50590 | vdb entry third party advisory |
http://securitytracker.com/id?1022204 | vdb entry third party advisory broken link |