|
|
Info |
Last Modified |
| 6 months ago |
|
|
|
|
Description |
NCR LifeKeeper contains a flaw that may lead to an unauthorized password disclosure. It is possible to gain access to the MS SQLServer sa password of the SQL server when using the Lifekeeper command "lkstop" from a command prompt, which may lead to a loss of confidentiality.
|
|
Classification |
Location:
Local Access Required
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
|
|
Solution |
Currently, there are no known workarounds or upgrades to correct this issue. However, NCR has released a patch to address this vulnerability.
|
|
Products |
|
LifeKeeper
 |
2.03D |
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|