First published: Tue May 30 2000(Updated: )
Microsoft SQL Server allows local users to obtain database passwords via the Data Transformation Service (DTS) package Properties dialog, aka the "DTS Password" vulnerability.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SQL Server | =7.0 | |
Microsoft SQL Server | =6.5 | |
=6.5 | ||
=7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0485 is considered a moderately severe vulnerability due to its potential to expose sensitive data.
To fix CVE-2000-0485, ensure you are using an updated version of Microsoft SQL Server that addresses this vulnerability.
CVE-2000-0485 affects local users of Microsoft SQL Server versions 6.5 and 7.0.
CVE-2000-0485 potentially allows local users to obtain database passwords.
While older versions of SQL Server are less commonly used today, CVE-2000-0485 remains a concern for systems that have not been updated.