VulnerabilityModified
CVE-2004-1609
SalesLogix 6.1 includes usernames, passwords, and other sensitive information in the headers of an HTTP response, which could allow remote attackers to gain access.
MEDIUM 5.0EPSS 1.78%
Does this matter?
Lower severity and a low EPSS score (1.78%). Track it; it rarely justifies an emergency change on its own.
Description
SalesLogix 6.1 includes usernames, passwords, and other sensitive information in the headers of an HTTP response, which could allow remote attackers to gain access.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.78% probability · 77th percentile
- CISA KEV
- Not listed
- Affected
- best software/saleslogix · saleslogix corporation/saleslogix
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/fulldisclosure/2004-10/0661.html
- http://marc.info/?l=bugtraq&m=109811852218478&w=2
- http://secunia.com/advisories/12883Patch, Vendor Advisory
- http://securitytracker.com/id?1011769
- http://www.osvdb.org/10946
- http://www.securityfocus.com/bid/11450Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17753
- http://archives.neohapsis.com/archives/fulldisclosure/2004-10/0661.html
- http://marc.info/?l=bugtraq&m=109811852218478&w=2
- http://secunia.com/advisories/12883Patch, Vendor Advisory
- http://securitytracker.com/id?1011769
- http://www.osvdb.org/10946
- http://www.securityfocus.com/bid/11450Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17753
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.