CVE-2006-5303: Low severity Securecomputing Safeword Remoteaccess vulnerability
Secure Computing SafeWord RemoteAccess 2.1 allows local users to obtain the UserCenter webportal password, database encryption keys, and signing keys by reading (1) base-64 encoded data in SERVERS\Web\Tomcat\usercenter\WEB-INF\login.conf and (2) plaintext data in SERVERS\Shared\signers.cfg. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5303?
CVE-2006-5303 is classified as a high severity vulnerability due to the exposure of sensitive data.
How do I fix CVE-2006-5303?
To fix CVE-2006-5303, it is recommended to restrict access to the configuration files and upgrade to a more secure version of the software.
Who is affected by CVE-2006-5303?
CVE-2006-5303 affects users of Secure Computing SafeWord RemoteAccess version 2.1.
What type of data is exposed in CVE-2006-5303?
CVE-2006-5303 exposes user passwords, database encryption keys, and signing keys.
Can local users exploit CVE-2006-5303?
Yes, local users can exploit CVE-2006-5303 to obtain sensitive information from the application.