Description
The encryptPassword function in Login.js in ManageEngine ServiceDesk Plus (SDP) 8012 and earlier uses a Caesar cipher for encryption of passwords in cookies, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2011-1510 | The encryptPassword function in Login.js in ManageEngine ServiceDesk Plus (SDP) 8012 and earlier uses a Caesar cipher for encryption of passwords in cookies, which makes it easier for remote attackers to obtain sensitive information by sniffing the network. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T22:28:41.803Z
Reserved: 2011-03-23T00:00:00.000Z
Link: CVE-2011-1509
No data.
Status : Deferred
Published: 2011-09-20T10:55:02.343
Modified: 2025-04-11T00:51:21.963
Link: CVE-2011-1509
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD