FileMaker Pro Client Authentication User Password Disclosure Vulnerability
BID:7315
Info
FileMaker Pro Client Authentication User Password Disclosure Vulnerability
| Bugtraq ID: | 7315 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 09 2003 12:00AM |
| Updated: | Apr 09 2003 12:00AM |
| Credit: | Discovery credited to Stephen White. |
| Vulnerable: |
FileMaker FileMaker Server 5.5 FileMaker FileMaker Server 5.0 FileMaker FileMaker Pro 6.0 Unlimited FileMaker FileMaker Pro 6.0 FileMaker FileMaker Pro 5.5 Unlimited FileMaker FileMaker Pro 5.5 FileMaker FileMaker Pro 5.0 |
| Not Vulnerable: | |
Discussion
FileMaker Pro Client Authentication User Password Disclosure Vulnerability
It has been reported that FileMaker Pro does not properly secure credentials during authentication. Because of this, an attacker may be able to gain access to information that could allow unauthorized access.
It has been reported that FileMaker Pro does not properly secure credentials during authentication. Because of this, an attacker may be able to gain access to information that could allow unauthorized access.
Solution / Fix
FileMaker Pro Client Authentication User Password Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
FileMaker Pro Client Authentication User Password Disclosure Vulnerability
References:
References:
- Security Considerations When Sharing Hosted Databases (FileMaker Inc.)
- FileMaker Pro network protocol sends passwords to any client attempting to conne (Stephen White
)