Vulnerability: Unprotected Credentials found in Installation log
search cancel

Vulnerability: Unprotected Credentials found in Installation log

book

Article ID: 217536

calendar_today

Updated On:

Products

Service Virtualization CA Application Test

Issue/Introduction

 
 
 
 

Passwords in the installation.log file are not encrypted and plainly visible.

We have recently purchased/installed DevTest 10.6 and our security team has shared the below findings:

During the penetration test, the configuration files on the our server were examined.

In the examination, it is seen that such passwords are stored encrypted in the files. However, in a document that was found to be a log file upon examination, this situation is in question.

It has been seen that it is not accessible because the password is kept open.

With the password obtained, it was possible to login into the database.

 
 

Environment

Release : 10.6

Component : CA Service Virtualization

Cause

N/A

Resolution

This will be addressed in DevTest 10.7

Additional Information

References