CVE-2010-3245
The automated-backup functionality in Blackboard Transact Suite (formerly Blackboard Commerce Suite) stores the (1) database username and (2) database password in cleartext in (a) script and (b) batch (.bat) files, which allows local users to obtain…
Does this matter?
Lower severity and a low EPSS score (0.88%). Track it; it rarely justifies an emergency change on its own.
Description
The automated-backup functionality in Blackboard Transact Suite (formerly Blackboard Commerce Suite) stores the (1) database username and (2) database password in cleartext in (a) script and (b) batch (.bat) files, which allows local users to obtain sensitive information by reading a file.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.88% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- blackboard/transact suite
- Source
- cve@mitre.org
References
- http://www.kb.cert.org/vuls/id/204055US Government Resource
- http://www.kb.cert.org/vuls/id/MAPG-86YPVMUS Government Resource
- http://www.kb.cert.org/vuls/id/204055US Government Resource
- http://www.kb.cert.org/vuls/id/MAPG-86YPVMUS Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.