漏洞标题
N/A
漏洞描述信息
DataSpider Servista 版本4.4及更早使用硬编码的加密密钥。DataSpider Servista 是数据集成软件。ScriptRunner 和 Amazon SQS 的 ScriptRunner 用于在 DataSpider Servista 上启动配置的进程。加密密钥嵌入在 ScriptRunner 和 Amazon SQS 的 ScriptRunner,对所有用户都通用。如果一个攻击者能够访问目标 DataSpider Servista 实例并获取 ScriptRunner 和/或 ScriptRunner 的启动设置文件,攻击者可能使用文件中加密的用户权限进行操作。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
漏洞类别
使用硬编码的凭证
漏洞标题
N/A
漏洞描述信息
DataSpider Servista version 4.4 and earlier uses a hard-coded cryptographic key. DataSpider Servista is data integration software. ScriptRunner and ScriptRunner for Amazon SQS are used to start the configured processes on DataSpider Servista. The cryptographic key is embedded in ScriptRunner and ScriptRunner for Amazon SQS, which is common to all users. If an attacker who can gain access to a target DataSpider Servista instance and obtain a Launch Settings file of ScriptRunner and/or ScriptRunner for Amazon SQS, the attacker may perform operations with the user privilege encrypted in the file. Note that DataSpider Servista and some of the OEM products are affected by this vulnerability. For the details of affected products and versions, refer to the information listed in [References].
CVSS信息
N/A
漏洞类别
N/A
漏洞标题
SAISON INFORMATION SYSTEMS DataSpider 信任管理问题漏洞
漏洞描述信息
SAISON INFORMATION SYSTEMS DataSpider是日本SAISON INFORMATION SYSTEMS公司的一个数据筛选器。 SAISON INFORMATION SYSTEMS DataSpider Servista 4.4及之前版本存在信任管理问题漏洞,该漏洞源于攻击者可以访问启动设置文件,使用文件中加密的用户权限执行操作。
CVSS信息
N/A
漏洞类别
信任管理问题