First published: Tue Dec 15 2020(Updated: )
The Software AG Terracotta Server OSS Docker image 5.4.1 contains a blank password for the root user. Systems deployed using affected versions of the Terracotta Server OSS container may allow a remote attacker to achieve root access with a blank password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Softwareag Terracotta Server Oss | =5.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35469 is a vulnerability in the Software AG Terracotta Server OSS Docker image 5.4.1 that allows remote attackers to achieve root access with a blank password.
The severity of CVE-2020-35469 is critical with a severity score of 9.8.
CVE-2020-35469 affects systems deployed using affected versions of the Terracotta Server OSS container, allowing a remote attacker to achieve root access with a blank password.
To fix CVE-2020-35469, update the Software AG Terracotta Server OSS Docker image to a version that does not contain a blank password for the root user.
More information about CVE-2020-35469 can be found at the following link: [CVE-2020-35469](https://github.com/donghyunlee00/CVE/blob/main/CVE-2020-35469).