REINER timeCard 6.05.07 installs a Microsoft SQL Server with an sa password that is hardcoded in the TCServer.jar file.
References
Link | Resource |
---|---|
https://www.compass-security.com/fileadmin/Research/Advisories/2021-12_CSNC-2021-012_timeCard_Hardcoded_Credentials.txt | Third Party Advisory |
Configurations
Information
Published : 2021-09-30 13:15
Updated : 2021-10-12 06:55
NVD link : CVE-2021-33583
Mitre link : CVE-2021-33583
JSON object : View
CWE
CWE-798
Use of Hard-coded Credentials
Products Affected
reiner-sct
- timecard