CVE Vulnerabilities

CVE-2002-0487

Published: Aug 12, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Intellisol Xpede 4.1 stores passwords in plaintext in a Javascript session timeout re-authentication capability, which could allow local users with access to gain privileges of other Xpede users by reading the password from the source file, e.g. from the browsers cache.

Affected Software

NameVendorStart VersionEnd Version
XpedeWorkforceroi4.1 (including)4.1 (including)
XpedeWorkforceroi7.0 (including)7.0 (including)

References