CVE-2006-1210
The web interface for IBM Tivoli Micromuse Netcool/NeuSecure 3.0.236 includes the MySQL database username and password in cleartext in body.phtml, which allows remote attackers to gain privileges by reading the source.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.57%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The web interface for IBM Tivoli Micromuse Netcool/NeuSecure 3.0.236 includes the MySQL database username and password in cleartext in body.phtml, which allows remote attackers to gain privileges by reading the source. NOTE: IBM has privately confirmed to CVE that a fix is available for these issues.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.57% probability · 74th percentile
- CISA KEV
- Not listed
- Affected
- micromuse/netcool neusecure
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/archive/1/427155/100/0/threaded
- http://www.securityfocus.com/bid/17032
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25270
- http://www.securityfocus.com/archive/1/427155/100/0/threaded
- http://www.securityfocus.com/bid/17032
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25270
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.