The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in plaintext in a log file which is readable by any user, aka the SQL Server 7.0 Service Pack Password vulnerability.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sql_server | Microsoft | 7.0 (including) | 7.0 (including) |
Sql_server | Microsoft | 7.0-sp1 (including) | 7.0-sp1 (including) |
Sql_server | Microsoft | 7.0-sp2 (including) | 7.0-sp2 (including) |