vendor:
Active Directory Sync (GADS) Tool
by:
Nathaniel Carew
7,5
CVSS
HIGH
Exposure of sensitive information
not provided
CWE
Product Name: Active Directory Sync (GADS) Tool
Affected Version From: All versions up to 3.1.3
Affected Version To: 3.1.3
Patch Exists: YES
Related CWE: not yet assigned
CPE: not provided
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Solaris
2013
Sense of Security – Security Advisory – SOS-13-001
Due to a weakness in the way the Java encryption algorithm (PBEwithMD5andDES) has been implemented in the GADS tool all stored credentials can be decrypted into plain-text. This includes all of the encrypted passwords stored in any end-users saved XML configuration file, such as Active Directory accounts, SMTP, Proxy details, LDAP and OAuth tokens, etc.
Mitigation:
Upgrade to version 3.1.6