CVE-2006-4676: Low severity TIBCO Rendezvous vulnerability
Published Sep 11, 2006
·Updated
TIBCO RendezVous 7.4.11 and earlier logs base64-encoded usernames and passwords in rvrd.db, which allows local users to obtain sensitive information by decoding the log file.
Affected Software
1 affected component
TIBCO Rendezvous<=7.4.11
Event History
Sep 11, 2006
CVE Published
05:04 PM
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4676?
CVE-2006-4676 is classified as a medium severity vulnerability due to the potential disclosure of sensitive information.
2
How do I fix CVE-2006-4676?
To address CVE-2006-4676, upgrade TIBCO RendezVous to version 7.4.12 or later, which eliminates the logging of sensitive information.
3
Who is affected by CVE-2006-4676?
CVE-2006-4676 affects local users of TIBCO RendezVous versions up to and including 7.4.11.
4
What information is exposed in CVE-2006-4676?
CVE-2006-4676 exposes base64-encoded usernames and passwords stored in the rvrd.db log file.
5
Can CVE-2006-4676 be exploited remotely?
CVE-2006-4676 cannot be exploited remotely as it requires local access to the vulnerable system.