McAfee ePolicy Orchestrator MSDE SA Account Information Disclosure Vulnerability
BID:8319
Info
McAfee ePolicy Orchestrator MSDE SA Account Information Disclosure Vulnerability
| Bugtraq ID: | 8319 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2003-0148 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 31 2003 12:00AM |
| Updated: | Jul 11 2009 10:56PM |
| Credit: | Discovery is credited to Andreas Junestam <[email protected]>. |
| Vulnerable: |
McAfee ePolicy Orchestrator 3.0 McAfee ePolicy Orchestrator 2.5.1 McAfee ePolicy Orchestrator 2.5 SP1 McAfee ePolicy Orchestrator 2.5 McAfee ePolicy Orchestrator 2.0 |
| Not Vulnerable: | |
Discussion
McAfee ePolicy Orchestrator MSDE SA Account Information Disclosure Vulnerability
McAfee ePolicy Orchestrator (ePO) may disclose the username and encrypted password for the database administrator account of the Microsoft Data Engine installation. Sending a specifically formatted HTTP request to the ePO server will return the server configuration file which contains this information.
McAfee ePolicy Orchestrator (ePO) may disclose the username and encrypted password for the database administrator account of the Microsoft Data Engine installation. Sending a specifically formatted HTTP request to the ePO server will return the server configuration file which contains this information.
Solution / Fix
References
McAfee ePolicy Orchestrator MSDE SA Account Information Disclosure Vulnerability
References:
References:
- Network Associates Security Bulletin 07/31/03 (Network Associates Inc.)