CVE-2013-3734
- Public Date:
- 2013-06-02
- Bugzilla:
- 971637: CVE-2013-3734 Embedded Jopr: Datasource password visible to administrator
The MITRE CVE dictionary describes this issue as:
Find out more about CVE-2013-3734 from the MITRE CVE dictionary dictionary and NIST NVD.
Statement
This issue is not a security flaw as, on its own, it does not cross a trust boundary in the system. In order to access the datasource password, you must be logged in to jopr as an administrative user, that has permission to (among other things) execute code, deploy applications and reset the password in question. The administrative user has the privileges to reset the password, hence, this does not expose any information that is not otherwise visible.
As administrative interfaces often display or allow the transmission of sensitive information, it is recommended best-practice that SSL is configured for the administrative console, regardless of this issue.
CVE description copyright © 2017, The MITRE Corporation
