Dell EMC Repository Manager (DRM) version 3.2 contains a plain-text password storage vulnerability. Proxy server user password is stored in a plain text in a local database. A local authenticated malicious user with access to the local file system may use the exposed password to access the with privileges of the compromised user.
The product stores a password in plaintext within resources such as memory or files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Emc_repository_manager | Dell | * | 3.2 (including) |