CVE-2014-4861: Critical severity delinea pam secret server vulnerability
Published Mar 9, 2018
·Updated
The Remote Desktop Launcher in Thycotic Secret Server before 8.6.000010 does not properly cleanup a temporary file that contains an encrypted password once a session has ended.
Affected Software
1 affected component
Thycotic Secret Server>=7.5.000000<=8.6.000009
Event History
Mar 9, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4861?
CVE-2014-4861 has been classified as a moderate severity vulnerability due to exposure of sensitive information.
2
How do I fix CVE-2014-4861?
To fix CVE-2014-4861, upgrade Thycotic Secret Server to version 8.6.000010 or later.
3
What specific issue does CVE-2014-4861 present?
CVE-2014-4861 presents an issue where a temporary file containing an encrypted password remains after a Remote Desktop session ends.
4
What versions of Thycotic Secret Server are affected by CVE-2014-4861?
Thycotic Secret Server versions between 7.5.000000 and 8.6.000009 are affected by CVE-2014-4861.
5
Is user data at risk due to CVE-2014-4861?
Yes, user data may be at risk as the temporary file with the encrypted password can be accessed if not properly cleaned up.