CVE-2008-4646

The Websense Reporter Module in Websense Enterprise 6.3.2 stores the SQL database system administrator password in plaintext in CreateDbInstall.log, which allows local users to gain privileges to the database.
Configurations

Configuration 1 (hide)

cpe:2.3:a:websense:enterpise:6.3.2:*:*:*:*:*:*:*

History

21 Nov 2024, 00:52

Type Values Removed Values Added
References () http://secunia.com/advisories/32264 - Vendor Advisory () http://secunia.com/advisories/32264 - Vendor Advisory
References () http://www.securityfocus.com/bid/31746 - () http://www.securityfocus.com/bid/31746 -
References () http://www.securitytracker.com/id?1021058 - () http://www.securitytracker.com/id?1021058 -
References () http://www.vupen.com/english/advisories/2008/2819 - () http://www.vupen.com/english/advisories/2008/2819 -
References () http://www.zebux.org/pub/Advisory/Advisory_Websense_Reporter_Password_Disclosure_200810.txt - () http://www.zebux.org/pub/Advisory/Advisory_Websense_Reporter_Password_Disclosure_200810.txt -

Information

Published : 2008-10-22 00:11

Updated : 2024-11-21 00:52


NVD link : CVE-2008-4646

Mitre link : CVE-2008-4646

CVE.ORG link : CVE-2008-4646


JSON object : View

Products Affected

websense

  • enterpise
CWE
CWE-255

Credentials Management Errors