In Delinea PAM Secret Server 11.4, it is possible for an attacker (with Administrator access to the Secret Server machine) to read the following data from a memory dump: the decrypted master key, database credentials (when SQL Server Authentication is enabled), the encryption key of RabbitMQ queue messages, and session cookies.
References
Configurations
No configuration.
History
21 Nov 2024, 09:01
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25649 - |
27 Aug 2024, 19:35
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CWE | CWE-316 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.7 |
14 Mar 2024, 03:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-14 03:15
Updated : 2024-11-21 09:01
NVD link : CVE-2024-25649
Mitre link : CVE-2024-25649
CVE.ORG link : CVE-2024-25649
JSON object : View
Products Affected
No product.
CWE
CWE-316
Cleartext Storage of Sensitive Information in Memory