4.6
CVE-2010-3244
- EPSS 0.29%
- Veröffentlicht 07.09.2010 18:00:02
- Zuletzt bearbeitet 16.06.2026 23:22:26
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
BbtsConnection_Edit.exe in Blackboard Transact Suite (formerly Blackboard Commerce Suite) before 3.6.0.2 relies on field names when determining whether it is appropriate to decrypt a connection.xml field value, which allows local users to discover the database password via a modified connection.xml file that contains an encrypted password in the <Server> field.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Blackboard ≫ Transact Suite Version <= 3.6.0.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.29% | 0.206 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://www.kb.cert.org/vuls/id/204055
http://www.kb.cert.org/vuls/id/MAPG-86YPVM