|
|
Info |
Last Modified |
| 10 months ago |
|
|
|
|
Description |
Control Manager contains a flaw that may allow a malicious user to replay a succesful login in order to gain access. The issue is triggered when the application is not configured to use HTTPS. It is possible that the flaw may allow unauthorized access resulting in a loss of integrity.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Authentication Management,
Information Disclosure
Impact:
Loss of Integrity
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified
OSVDB:
Web Related,
Concern
|
|
Technical |
HTTP connections should not be considered secure in any application. Any application which is configured to use a plain HTTP connection for authentication will be vulnerable to password sniffing and decoding attacks. This vulnerability should be considered a flaw in configuration, rather than a flaw in the application.
|
|
Solution |
Enable HTTPS communication for login.
|
|
Products |
|
Control Manager Enterprise Edition
 |
3.0 |
|
|
|
|
Credit |
- Dennis Rand - advisory
cirt.dk - Danish Computer Incident Response Team
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|