Sparx Systems Enterprise Architect Password Disclosure Vulnerability
BID:57946
Info
Sparx Systems Enterprise Architect Password Disclosure Vulnerability
| Bugtraq ID: | 57946 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 13 2013 12:00AM |
| Updated: | Feb 13 2013 12:00AM |
| Credit: | Holm Diening |
| Vulnerable: |
Sparx Systems Enterprise Architect 9.3.931 |
| Not Vulnerable: | |
Discussion
Sparx Systems Enterprise Architect Password Disclosure Vulnerability
Enterprise Architect is prone to a password-disclosure vulnerability due to a design error.
Attackers can exploit this issue to obtain sensitive information that may aid in launching further attacks.
Enterprise Architect 9.3.931 is vulnerable; other versions may also be affected.
Enterprise Architect is prone to a password-disclosure vulnerability due to a design error.
Attackers can exploit this issue to obtain sensitive information that may aid in launching further attacks.
Enterprise Architect 9.3.931 is vulnerable; other versions may also be affected.
Exploit / POC
Sparx Systems Enterprise Architect Password Disclosure Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
Sparx Systems Enterprise Architect Password Disclosure Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Sparx Systems Enterprise Architect Password Disclosure Vulnerability
References:
References:
- Enterprise Architect Home Page (Sparx Systems)
- Simple password obfuscation in Enterprise Architect (Diening, Holm)