PrimeBase SQL Database Server Administrative Server Password Storage Vulnerability
BID:9087
Info
PrimeBase SQL Database Server Administrative Server Password Storage Vulnerability
| Bugtraq ID: | 9087 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 22 2003 12:00AM |
| Updated: | Nov 22 2003 12:00AM |
| Credit: | Discovery credited to Larry W. Cashdollar. |
| Vulnerable: |
SNAP Innovation PrimeBase SQL Database Server 4.2 |
| Not Vulnerable: |
SNAP Innovation PrimeBase SQL Database Server 4.2.29 |
Discussion
PrimeBase SQL Database Server Administrative Server Password Storage Vulnerability
A problem has been reported in the storage of credentials in PrimeBase SQL Database Server. Because of this, it may be possible for an attacker to gain unauthorized access to resources.
A problem has been reported in the storage of credentials in PrimeBase SQL Database Server. Because of this, it may be possible for an attacker to gain unauthorized access to resources.
Exploit / POC
PrimeBase SQL Database Server Administrative Server Password Storage Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
Solution / Fix
PrimeBase SQL Database Server Administrative Server Password Storage Vulnerability
Solution:
The vendor has released fixes to address this issue on affected platforms.
SNAP Innovation PrimeBase SQL Database Server 4.2
Solution:
The vendor has released fixes to address this issue on affected platforms.
SNAP Innovation PrimeBase SQL Database Server 4.2
-
SNAP Innovation PrimeBase SQL Database Server 4.2.29
http://www.primebase.com/ftp/releases/4229/
References
PrimeBase SQL Database Server Administrative Server Password Storage Vulnerability
References:
References:
- PrimeBase Homepage (SNAP Innovation)
- PrimeBase SQL Database server cleartext password storage. (fwd) ("Larry W. Cashdollar"
)