REINER timeCard 6.05.07 installs a Microsoft SQL Server with an sa password that is hardcoded in the TCServer.jar file.
References
Link | Resource |
---|---|
https://www.compass-security.com/fileadmin/Research/Advisories/2021-12_CSNC-2021-012_timeCard_Hardcoded_Credentials.txt | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2021-09-30 20:15
Updated : 2021-10-12 13:55
NVD link : CVE-2021-33583
Mitre link : CVE-2021-33583
CVE.ORG link : CVE-2021-33583
JSON object : View
Products Affected
reiner-sct
- timecard
CWE
CWE-798
Use of Hard-coded Credentials