Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
CollabNet ScrumWorks Basic 1.8.4 uses cleartext credentials for network communication and the internal database, which makes it easier for context-dependent attackers to obtain sensitive information by (1) sniffing the network for transmissions of Java objects or (2) reading the database.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
CollabNet ScrumWorks Basic Server证书敏感信息泄露漏洞
Vulnerability Description
CollabNet ScrumWorks Basic 1.8.4版本使用明文文本证书用于网络通信及内部数据库。上下文攻击者更容易通过(1)嗅探用于传输Java对象的网络,或者(2)读取数据库获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A