CVE-2015-2998
SysAid Help Desk <15.2 - Info Disclosure
Title source: llmDescription
SysAid Help Desk before 15.2 uses a hardcoded encryption key, which makes it easier for remote attackers to obtain sensitive information, as demonstrated by decrypting the database password in WEB-INF/conf/serverConf.xml.
Exploits (1)
References (5)
Scores
EPSS
0.6216
EPSS Percentile
98.4%
Details
CWE
CWE-200
Status
published
Products (1)
sysaid/sysaid
< 15.1
Published
Jun 08, 2015
Tracked Since
Feb 18, 2026