CVE-2019-13348
HIGHENG Knowage < 6.4 - Insufficiently Protected Credentials
Title source: ruleDescription
In Knowage through 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source credentials in cleartext, which includes databases.
Scores
CVSS v3
8.8
EPSS
0.0111
EPSS Percentile
78.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-522
Status
published
Affected Products (1)
eng/knowage
< 6.4
Timeline
Published
Aug 28, 2019
Tracked Since
Feb 18, 2026