First published: Tue May 30 2000(Updated: )
The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in plaintext in a log file which is readable by any user, aka the "SQL Server 7.0 Service Pack Password" vulnerability.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SQL Server | =7.0-sp1 | |
Microsoft SQL Server | =7.0 | |
Microsoft SQL Server | =7.0-sp2 | |
=7.0 | ||
=7.0-sp1 | ||
=7.0-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0402 is classified as a critical vulnerability due to the exposure of sensitive credentials.
To fix CVE-2000-0402, users should upgrade to a newer version of Microsoft SQL Server that does not store the 'sa' account password in plaintext.
CVE-2000-0402 affects Microsoft SQL Server 7.0, including service packs SP1 and SP2.
The potential risks of CVE-2000-0402 include unauthorized access to the SQL Server by exposing the 'sa' password to any user with access to the log file.
Disabling Mixed Mode authentication can serve as a temporary workaround for CVE-2000-0402 until the software is upgraded.