First published: Thu May 05 2011(Updated: )
The application server in Trustwave WebDefend Enterprise before 5.0 uses hardcoded console credentials, which makes it easier for remote attackers to read security-event data by using the remote console GUI to connect to the management port.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Trustwave WebDefend | <=3.0 | |
Trustwave WebDefend | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0756 is considered a moderate severity vulnerability due to the use of hardcoded console credentials.
To fix CVE-2011-0756, upgrade to Trustwave WebDefend version 5.0 or later which eliminates the hardcoded credentials.
CVE-2011-0756 affects Trustwave WebDefend Enterprise versions prior to 5.0.
Organizations using Trustwave WebDefend Enterprise versions up to 3.0 are impacted by CVE-2011-0756.
The vulnerability in CVE-2011-0756 allows remote attackers to exploit hardcoded credentials to access security event data.