Combodo iTop is a web based IT Service Management tool. An attacker accessing a backup file or the database can read some passwords for misconfigured Users. This issue has been addressed in version 3.2.0 and all users are advised to upgrade. Users unable to upgrade are advised to encrypt their backups independently of the iTop application. ### Patches Sanitize parameter ### References N°7631 - Password is stored in clear in the database.
History

Thu, 07 Nov 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 07 Nov 2024 18:15:00 +0000

Type Values Removed Values Added
Description Combodo iTop is a web based IT Service Management tool. An attacker accessing a backup file or the database can read some passwords for misconfigured Users. This issue has been addressed in version 3.2.0 and all users are advised to upgrade. Users unable to upgrade are advised to encrypt their backups independently of the iTop application. ### Patches Sanitize parameter ### References N°7631 - Password is stored in clear in the database.
Title Password is stored in clear in the database in Combodo iTop
Weaknesses CWE-312
References
Metrics cvssV3_0

{'score': 3.4, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-11-07T17:59:18.617Z

Updated: 2024-11-07T18:32:36.129Z

Reserved: 2024-11-04T17:46:16.776Z

Link: CVE-2024-51993

cve-icon Vulnrichment

Updated: 2024-11-07T18:32:20.936Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-07T18:15:18.203

Modified: 2024-11-08T19:01:03.880

Link: CVE-2024-51993

cve-icon Redhat

No data.