Description
Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server. Unauthenticated user can retrieve database password in plaintext in certain situations
Problem types
CWE-359: Exposure of Private Personal Information to an Unauthorized Actor
CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere
Product status
6.0.163
Credits
Pasi Orovuo, Solita Oy
Henri Hämäläinen, Solita Oy
Samu Ahvenainen, Solita Oy
References
sparxsystems.com/products/procloudserver/6.1/history.html