Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server. Unauthenticated user can retrieve database password in plaintext in certain situations
The vulnerability encompasses two classes of errors: disclosure of private personal data to unauthorized entities (CWE-359) and exposure of sensitive system information outside the permitted control zone (CWE-497). Under specific conditions, the application exposes the database password in plaintext form without verifying the identity of the requester. An attacker can remotely, without logging in, obtain access to this data over the network.
An attacker can obtain database credentials, enabling unauthorized access to its resources, reading, modification, or exfiltration of data stored in the system.
Apply patches available from the vendor according to the references: https://sparxsystems.com/products/procloudserver/6.1/history.html
Sparx Systems Pty Ltd. Sparx Pro Cloud Server — specific versions indicated in the vendor references (release history available at the reference address)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:C/RE:M/U:RedSparxsystems Pro Cloud Server
APPSparxsystems6.0.163
Related vulnerabilities
Sparx Pro Cloud Server — SQL injection bez uwierzytelnienia przez pominięcie parametru
Plaintext Storage haseł w Sparx Pro Cloud Server z OpenID
SQL Injection w Sparx Pro Cloud Server — nieautoryzowany dostęp do bazy danych
Sparx Pro Cloud Server is vulnerable to Broken Access Control within communication with the database. Due to l...
Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_internal_artifact.php endpoint. T...