An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. Insecure permissions for the serverconfig registry key (under JavaSoft\Prefs\de\igel\rm\config in HKEY_LOCAL_MACHINE\SOFTWARE) allow an unprivileged local attacker to read the encrypted dbuser and dbpassword values for the UMS superuser.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2022-06-09T00:45:20

Updated: 2024-08-03T04:49:43.831Z

Reserved: 2022-02-23T00:00:00

Link: CVE-2022-25804

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-06-09T04:15:10.833

Modified: 2022-06-17T16:00:36.507

Link: CVE-2022-25804

cve-icon Redhat

No data.