Information Disclosure Vulnerability in Symantec Reporting Server
CVE-2007-3022
Currently unrated
Key Information:
- Vendor
- Symantec
- Vendor
- CVE Published:
- 5 June 2007
Summary
The Symantec Reporting Server, along with various versions of Symantec Client Security and Symantec AntiVirus Corporate Edition, poses a risk by revealing password hashes after unsuccessful login attempts. This flaw may enable remote attackers to efficiently execute brute force attacks on user accounts, further compromising the security of sensitive data.
References
Timeline
Vulnerability published
Vulnerability Reserved