Tomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
The product stores a password in a configuration file that might be accessible to actors who do not know the password.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Analytics | Sonicwall | * | 2.5.0.4-r7 (including) |
Global_management_system | Sonicwall | * | 9.3.2 (excluding) |
Global_management_system | Sonicwall | 9.3.2 (including) | 9.3.2 (including) |
Global_management_system | Sonicwall | 9.3.2-sp1 (including) | 9.3.2-sp1 (including) |