|The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a database and tools to fix them.|
Ingres: incorrect authentication
Synthesis of the vulnerability
Under Windows, the second user who logs into Ingres is connected as the first user.
Impacted products: Ingres Database.
Severity of this bulletin: 2/4.
Consequences of an intrusion: user access/rights.
Hacker's origin: user account.
Number of vulnerabilities in this bulletin: 2.
Creation date: 20/12/2007.
Revision date: 27/12/2007.
Références of this threat: 415703, BID-2695, CAID 35970, CERTA-2007-AVI-558, CVE-2007-6334, VIGILANCE-VUL-7437.
Description of the vulnerability
The Microsoft IIS web server supports IWA (Integrated Windows Authentication) authentication. Two vulnerabilities related to this authentication affect Ingres.
With Ingres r3 and Ingres 2006, when a user is connected, and if another user authenticates, an error occurs and his access is rejected. [severity:2/4]
With Ingres 2.6 and 2.5, when a user is connected, and if another user authenticates, he accesses to the account of the first user. [severity:2/4],
Full Vigil@nce bulletin... (Free trial)
Computer vulnerabilities tracking service
Vigil@nce provides an application vulnerability watch. The Vigil@nce vulnerability database contains several thousand vulnerabilities. The Vigil@nce computer vulnerability tracking service alerts your teams of vulnerabilities or threats impacting your information system. The Vigil@nce security watch publishes vulnerability bulletins about threats impacting the information system.