
CVE-2020-5805
https://notcve.org/view.php?id=CVE-2020-5805
08 Jan 2021 — In Marvell QConvergeConsole GUI <= 5.5.0.74, credentials are stored in cleartext in tomcat-users.xml. OS-level users on the QCC host who are not authorized to use QCC may use the plaintext credentials to login to QCC. En Marvell QConvergeConsole versiones anteriores a 5.5.0.74 incluyéndola, las credenciales son almacenadas en texto plano en el archivo tomcat-users.xml. Los usuarios OS-level en el host del componente QCC que no están autorizados para utilizar QCC pueden usar las credenciales de texto pl... • https://www.tenable.com/security/research/tra-2021-01 • CWE-312: Cleartext Storage of Sensitive Information •

CVE-2020-5804
https://notcve.org/view.php?id=CVE-2020-5804
08 Jan 2021 — Marvell QConvergeConsole GUI <= 5.5.0.74 is affected by a path traversal vulnerability. The deleteEventLogFile method of the GWTTestServiceImpl class lacks proper validation of a user-supplied path prior to using it in file deletion operations. An authenticated, remote attacker can leverage this vulnerability to delete arbitrary remote files as SYSTEM or root. Marvell QConvergeConsole GUI versiones anteriores a 5.5.0.74 incluyéndola, está afectado por una vulnerabilidad de salto de ruta. El método dele... • https://www.tenable.com/security/research/tra-2021-01 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •