vendor:
OracleAS TopLink Mapping Workbench
by:
Martin
7.5
CVSS
HIGH
Weak Encryption
326
CWE
Product Name: OracleAS TopLink Mapping Workbench
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2004
OracleAS TopLink Mapping Workbench Weak Encryption Vulnerability
OracleAS TopLink Mapping Workbench is reported to use a weak encryption algorithm when storing passwords in XML files. A proof-of-concept has been released that demonstrates how passwords are encrypted, by reversing the process described in the proof-of-concept, an attacker with access to XML files generated by the software could decrypt embedded passwords. The encryption scheme uses a simplistic substitution cipher and then appends a static string to the end of the encrypted password.
Mitigation:
Ensure that the latest version of OracleAS TopLink Mapping Workbench is installed and that the encryption algorithm is updated to a stronger one.