First published: Fri Sep 16 2022(Updated: )
When logging in to a VBASE runtime project via Web-Remote, the product uses XOR with a static initial key to obfuscate login messages. An unauthenticated remote attacker with the ability to capture a login session can obtain the login credentials.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
VISAM VBASE | =11.7.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.