The default configuration of PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 uses cleartext for storage of credentials in a database, which makes it easier for context-dependent attackers to obtain sensitive information via unspecified vectors.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://www.kb.cert.org/vuls/id/437385 | third party advisory us government resource |