CVE-2000-0199: Weak Encryption
When a new SQL Server is registered in Enterprise Manager for Microsoft SQL Server 7.0 and the "Always prompt for login name and password" option is not set, then the Enterprise Manager uses weak encryption to store the login ID and password.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Enable the 'Always prompt for login name and password' option in Enterprise Manager so it does not store login IDs and passwords using weak encryption.
Enterprise Manager for Microsoft SQL Server 7.0 Always prompt for login name and password = enabled
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0199?
CVE-2000-0199 has a medium severity rating due to weak encryption of login credentials.
How do I fix CVE-2000-0199?
To fix CVE-2000-0199, ensure that the "Always prompt for login name and password" option is enabled in SQL Server 7.0.
What software versions are affected by CVE-2000-0199?
CVE-2000-0199 specifically affects Microsoft SQL Server 7.0.
What vulnerabilities are associated with weak encryption in CVE-2000-0199?
CVE-2000-0199 can lead to unauthorized access as login ID and passwords are stored with weak encryption.
Is there a risk if I use Microsoft SQL Server 7.0 with the default settings in CVE-2000-0199?
Yes, using Microsoft SQL Server 7.0 with default settings presents a risk of credential exposure due to weak encryption.