Vulnerability Name:

CVE-2000-0485 (CCN-4582)

Assigned:2000-05-25
Published:2000-05-25
Updated:2018-10-12
Summary:Microsoft SQL Server allows local users to obtain database passwords via the Data Transformation Service (DTS) package Properties dialog, aka the "DTS Password" vulnerability.
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: BugTraq Mailing List, Thu May 25 2000 - 23:23:36 CDT
Steal Passwords Using SQL Server EM

Source: CCN
Type: BugTraq Mailing List, Tue May 30 2000 - 11:17:50 CDT
Fw: Steal Passwords Using SQL Server EM

Source: MITRE
Type: CNA
CVE-2000-0485

Source: MITRE
Type: CNA
CVE-2000-0654

Source: CCN
Type: CIAC Information Bulletin K-059
Microsoft "DTS Password" Vulnerability

Source: CCN
Type: Microsoft Security Bulletin MS00-041
Patch Available for 'DTS Password' Vulnerability

Source: CCN
Type: Microsoft Security Bulletin MS01-004
Patch Available for New Variant of File Fragment Reading via .HTR Vulnerability

Source: CCN
Type: Microsoft Security Bulletin MS01-041
Malformed RPC Request Can Cause Service Failure

Source: CCN
Type: Microsoft Security Bulletin MS02-001
Trusting Domains Do Not Verify Domain Membership of SIDs in Authorization Data

Source: CCN
Type: Microsoft Security Bulletin MS02-018
Cumulative Patch for Internet Information Services (Q319733)

Source: CCN
Type: OSVDB ID: 1369
Microsoft SQL Server DTS Password Disclosure

Source: CCN
Type: OSVDB ID: 1461
Microsoft Enterprise Manager DTS Package Password Disclosure

Source: BUGTRAQ
Type: UNKNOWN
20000530 Fw: Steal Passwords Using SQL Server EM

Source: BID
Type: UNKNOWN
1292

Source: CCN
Type: BID-1292
Microsoft SQL Server DTS Password Disclosure Vulnerability

Source: CCN
Type: BID-1466
Microsoft SQL Server Enterprise Manager Password Disclosure Vulnerability

Source: MS
Type: UNKNOWN
MS00-041

Source: XF
Type: UNKNOWN
mssql-dts-reveal-passwords(4582)

Source: XF
Type: UNKNOWN
mssql-dts-reveal-passwords(4582)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:microsoft:sql_server:6.5:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:sql_server:7.0:-:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:microsoft:sql_server:*:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:sql_server:7.0:-:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    microsoft sql server 6.5
    microsoft sql server 7.0
    microsoft sql server *
    microsoft sql server 7.0