The screensharing feature in the Admin application in Apple Xsan before 2.2 places a cleartext username and password in a URL within an error dialog, which allows physically proximate attackers to obtain credentials by reading this dialog.
Weaknesses in this category are related to the design and implementation of data confidentiality and integrity. Frequently these deal with the use of encoding techniques, encryption libraries, and hashing algorithms. The weaknesses in this category could lead to a degradation of the quality data if they are not addressed.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/53232 | vdb entry |
http://www.securityfocus.com/bid/36385 | vdb entry patch |
http://osvdb.org/58133 | vdb entry |
http://www.vupen.com/english/advisories/2009/2644 | vdb entry patch vendor advisory |
http://www.securitytracker.com/id?1022904 | vdb entry |
http://support.apple.com/kb/HT3797 | patch vendor advisory |
http://lists.apple.com/archives/security-announce/2009/Sep/msg00005.html | patch vendor advisory |
http://secunia.com/advisories/36673 | third party advisory |