2 results (0.004 seconds)

CVSS: 2.1EPSS: 0%CPEs: 1EXPL: 0

Citrix Metaframe Password Manager 2.5 and earlier stores a password in cleartext although it is obfuscated when presented to a user, which allows users to view their secondary passwords even if it is not allowed by policy. • http://securitytracker.com/id?1018077 http://support.citrix.com/article/CTX105800 http://support.citrix.com/kb/entry.jspa?entryID=5970&categoryID=254 http://support.citrix.com/kb/entry.jspa?externalID=CTX105762 http://www.securityfocus.com/bid/24041 •

CVSS: 2.1EPSS: 0%CPEs: 1EXPL: 0

The Citrix MetaFrame Password Manager 2.0, when a central credential store is not configured, does not encrypt passwords entered immediately after executing the First Time User Wizards, which allows local users to gain sensitive information. • http://marc.info/?l=bugtraq&m=108127948610311&w=2 http://secunia.com/advisories/11293 http://securitytracker.com/id?1009659 http://support.citrix.com/kb/entry.jspa?entryID=4062&categoryID=256 http://www.osvdb.org/4942 http://www.securityfocus.com/bid/10049 https://exchange.xforce.ibmcloud.com/vulnerabilities/15737 •