CVE-2000-0199

Microsoft SQL Server 7.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

When a new SQL Server is registered in Enterprise Manager for Microsoft SQL Server 7.0 and the "Always prompt for login name and password" option is not set, then the Enterprise Manager uses weak encryption to store the login ID and password.

References (1)

Core 1
Core References
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1055

Scores

EPSS 0.0145
EPSS Percentile 70.9%

Details

Status published
Products (1)
microsoft/sql_server 7.0
Published Mar 14, 2000
Tracked Since Feb 18, 2026