In Delinea PAM Secret Server 11.4, it is possible for an attacker (with Administrator access to the Secret Server machine) to read the following data from a memory dump: the decrypted master key, database credentials (when SQL Server Authentication is enabled), the encryption key of RabbitMQ queue messages, and session cookies.
oryginał ENCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:NDelinea Secret Server
APPDelinea11.4.000000
Powiązane podatności
Delinea Secret Server — brak weryfikacji integralności pakietów aktualizacji
Delinea Secret Server before 11.7.000001 allows attackers to bypass authentication via the SOAP API in SecretS...
In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or w...
Podatność w ramach improper authentication w Delinea Inc. Secret Server On-Prem (moduły RPC Password Rotation)...
Delinea addressed a reported case on Secret Server v11.7.31 (protocol handler version 6.0.3.26) where, within ...