SmartFilter Web Gateway Security 4.2.1.00 stores user credentials in cleartext in admin_backup.xml files and uses insecure permissions for these files, which allows local users to gain privileges. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/49338 | vdb entry |
http://archives.neohapsis.com/archives/fulldisclosure/2009-03/0314.html | mailing list |
http://secunia.com/advisories/34390 | third party advisory vendor advisory |