The Jedox Palo 1.5 client transmits the password in cleartext, which might allow remote attackers to obtain the password by sniffing the network, as demonstrated by starting Excel with the Palo plugin, opening a cube, and performing an Insert View.
References
Configurations
History
21 Nov 2024, 00:33
Type | Values Removed | Values Added |
---|---|---|
References | () http://85.10.222.122/mantis/public_show_bug.php?bug_id=452 - | |
References | () http://osvdb.org/45754 - |
Information
Published : 2007-07-05 20:30
Updated : 2024-11-21 00:33
NVD link : CVE-2007-3581
Mitre link : CVE-2007-3581
CVE.ORG link : CVE-2007-3581
JSON object : View
Products Affected
jedox
- palo
CWE