EMC ESRS Policy Manager prior to 6.8 contains an undocumented account (OpenDS admin) with a default password. A remote attacker with the knowledge of the default password may login to the system and gain administrator privileges to the local LDAP directory server.
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1038840 | issue tracking vdb entry third party advisory |
http://seclists.org/fulldisclosure/2017/Jul/13 | third party advisory mailing list |