First published: Thu Oct 27 2005(Updated: )
The installation of ON Symantec Discovery 4.5.x and Symantec Discovery 6.0 creates the (1) DiscoveryWeb and (2) DiscoveryRO database accounts with null passwords, which could allow attackers to gain privileges or prevent Discovery from running by setting another password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Discovery | =6.0 | |
Symantec On Command Discovery | =standard_4.5 | |
Symantec On Command Discovery | =web_4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3316 is classified as a high-severity vulnerability due to the potential for unauthorized access and privilege escalation.
To fix CVE-2005-3316, ensure that the DiscoveryWeb and DiscoveryRO database accounts are configured with strong, non-null passwords.
CVE-2005-3316 affects Symantec Discovery versions 4.5.x and 6.0.
Leaving accounts with null passwords as per CVE-2005-3316 can allow attackers to gain unauthorized privileges and disrupt the functionality of Discovery.
While specific exploitation metrics for CVE-2005-3316 are less reported, vulnerabilities that enable unauthorized access are typically targeted by attackers.