First published: Mon Jan 24 2011(Updated: )
CollabNet ScrumWorks Basic 1.8.4 uses cleartext credentials for network communication and the internal database, which makes it easier for context-dependent attackers to obtain sensitive information by (1) sniffing the network for transmissions of Java objects or (2) reading the database.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
CollabNet ScrumWorks | =1.8.4-basic |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0410 is considered a high severity vulnerability due to its potential to expose sensitive credentials.
To fix CVE-2011-0410, it is recommended to configure the application to use encrypted communication channels for all network transmissions.
CVE-2011-0410 can be exploited by attackers through network sniffing or direct access to the database to capture cleartext credentials.
CVE-2011-0410 specifically affects CollabNet ScrumWorks Basic version 1.8.4.
Yes, CVE-2011-0410 puts sensitive data at risk since it allows attackers to obtain cleartext credentials used for network communication.