First published: Mon Feb 08 2010(Updated: )
Sun Cluster 2.2, when HA-Oracle or HA-Sybase DBMS services are used, stores database credentials in cleartext in a cluster configuration file, which allows local users to obtain sensitive information by reading this file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Solaris Cluster | =2.2 | |
=2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1588 is classified as a medium severity vulnerability due to the exposure of database credentials in cleartext.
To fix CVE-2003-1588, ensure that the database credentials are stored securely and avoid using cleartext storage in configuration files.
CVE-2003-1588 affects Sun Cluster version 2.2 when used with HA-Oracle or HA-Sybase DBMS services.
CVE-2003-1588 exposes sensitive database credentials that can be accessed by local users.
Local users with access to the cluster configuration file can exploit CVE-2003-1588 to obtain sensitive information.