First published: Wed Nov 21 2007(Updated: )
AdventNet EventLog Analyzer build 4030 for Windows, and possibly other versions and platforms, installs a mysql instance with a default "root" account without a password, which allows remote attackers to gain privileges and modify logs. Fixed in EventLog Analyzer Build 6000.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ManageEngine EventLog Analyzer | =build_4030 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6081 is considered to be a critical vulnerability due to the lack of password protection on the 'root' MySQL account.
To fix CVE-2007-6081, upgrade to EventLog Analyzer Build 6000 or later, which addresses the password security issue.
CVE-2007-6081 affects AdventNet EventLog Analyzer version build 4030 for Windows and potentially other versions and platforms.
Remote attackers can gain privileges and modify logs due to the default unprotected 'root' MySQL account.
As a temporary workaround, securing the MySQL 'root' account with a strong password can help mitigate the risk of CVE-2007-6081.