First published: Mon Sep 11 2006(Updated: )
TIBCO RendezVous 7.4.11 and earlier logs base64-encoded usernames and passwords in rvrd.db, which allows local users to obtain sensitive information by decoding the log file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO Rendezvous | <=7.4.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4676 is classified as a medium severity vulnerability due to the potential disclosure of sensitive information.
To address CVE-2006-4676, upgrade TIBCO RendezVous to version 7.4.12 or later, which eliminates the logging of sensitive information.
CVE-2006-4676 affects local users of TIBCO RendezVous versions up to and including 7.4.11.
CVE-2006-4676 exposes base64-encoded usernames and passwords stored in the rvrd.db log file.
CVE-2006-4676 cannot be exploited remotely as it requires local access to the vulnerable system.