CVE-2016-10104

Information Disclosure can occur in sshProfiles.jsd in Hitek Software's Automize because of the Read attribute being set for Users. This allows an attacker to recover encrypted passwords for SSH/SFTP profiles. Verified in all 10.x versions up to and including 10.25, and all 11.x versions up to and including 11.14.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hiteksoftware:automize:10.02:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:10.03:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:10.11:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:10.12:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:10.20:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:10.21:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:11.02:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:10.06:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:10.07:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:10.15:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:10.16:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:11.06:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:10.00:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:10.14:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:11.03:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:10.09:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:11.11:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:11.13:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:10.17:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:10.23:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:11.12:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:11.14:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:10.08:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:11.04:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:10.01:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:10.05:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:11.07:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:10.24:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:11.05:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:10.04:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:10.25:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:10.22:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:10.13:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:11.09:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:11.00:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:11.01:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:10.19:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:11.08:*:*:*:*:*:*:*
cpe:2.3:a:hiteksoftware:automize:10.18:*:*:*:*:*:*:*

Information

Published : 2017-01-22 23:59

Updated : 2017-03-15 18:59


NVD link : CVE-2016-10104

Mitre link : CVE-2016-10104


JSON object : View

CWE
CWE-326

Inadequate Encryption Strength

Advertisement

dedicated server usa

Products Affected

hiteksoftware

  • automize