Tomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Analytics | Sonicwall | * | 2.5.0.4-r7 (including) |
Global_management_system | Sonicwall | * | 9.3.2 (excluding) |
Global_management_system | Sonicwall | 9.3.2 (including) | 9.3.2 (including) |
Global_management_system | Sonicwall | 9.3.2-sp1 (including) | 9.3.2-sp1 (including) |