Vulnerability Name: | CVE-2007-3022 (CCN-34740) | ||||||||
Assigned: | 2007-06-05 | ||||||||
Published: | 2007-06-05 | ||||||||
Updated: | 2017-07-29 | ||||||||
Summary: | Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, displays the password hash for a user after a failed login attempt, which makes it easier for remote attackers to conduct brute force attacks. | ||||||||
CVSS v3 Severity: | 3.5 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-3022 Source: OSVDB Type: UNKNOWN 36108 Source: CCN Type: SA25543 Symantec Reporting Server Three Vulnerabilities Source: SECUNIA Type: UNKNOWN 25543 Source: CCN Type: SECTRACK ID: 1018196 Symantec Reporting Server Lets Remote Users Execute Arbitrary Code or Obtain the Administrative Password Source: CCN Type: OSVDB ID: 36108 Symantec Multiple Products Reporting Server Failed Login Password Hash Remote Disclosure Source: BID Type: UNKNOWN 24312 Source: CCN Type: BID-24312 Symantec Reporting Server Password Information Disclosure Vulnerability Source: CCN Type: BID-24325 Symantec Reporting Server Authentication Bypass Vulnerability Source: SECTRACK Type: UNKNOWN 1018196 Source: CCN Type: SYM07-011 Symantec Reporting Server Password Disclosure Source: CONFIRM Type: Patch http://www.symantec.com/avcenter/security/Content/2007.06.05.html Source: VUPEN Type: UNKNOWN ADV-2007-2074 Source: XF Type: UNKNOWN symantec-reporting-information-disclosure(34740) Source: XF Type: UNKNOWN symantec-reporting-information-disclosure(34740) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |