The application fails to prevent users from connecting to it over unencrypted connections. An attacker able to modify a legitimate users network traffic could bypass the applications use of SSL/TLS encryption and use the application as a platform for attacks against its users.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Engineer’s_toolset | Solarwinds | 2020.2.6-hotfix_4 (including) | 2020.2.6-hotfix_4 (including) |