Dell EMC Repository Manager (DRM) version 3.2 contains a plain-text password storage vulnerability. Proxy server user password is stored in a plain text in a local database. A local authenticated malicious user with access to the local file system may use the exposed password to access the with privileges of the compromised user.
References
Configurations
Information
Published : 2021-07-19 15:15
Updated : 2021-08-02 09:49
NVD link : CVE-2020-5315
Mitre link : CVE-2020-5315
JSON object : View
CWE
CWE-522
Insufficiently Protected Credentials
Products Affected
dell
- emc_repository_manager