Pearson ProctorCache before 2015.1.17 uses the same hardcoded password across different customers' installations, which allows remote attackers to modify test metadata or cause a denial of service (test disruption) by leveraging knowledge of this password.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://www.kb.cert.org/vuls/id/626420 | third party advisory us government resource |