Vulnerability Description
Microsoft Enterprise Manager allows local users to obtain database passwords via the Data Transformation Service (DTS) package Registered Servers Dialog dialog, aka a variant of the "DTS Password" vulnerability.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Sql Server | 7.0 |
References
- http://www.securityfocus.com/bid/1466PatchVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-04
- https://exchange.xforce.ibmcloud.com/vulnerabilities/4582
- http://www.securityfocus.com/bid/1466PatchVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-04
- https://exchange.xforce.ibmcloud.com/vulnerabilities/4582
FAQ
What is CVE-2000-0654?
CVE-2000-0654 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Microsoft Enterprise Manager allows local users to obtain database passwords via the Data Transformation Service (DTS) package Registered Servers Dialog dialog, aka a variant of the "DTS Password" vul...
How severe is CVE-2000-0654?
CVE-2000-0654 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2000-0654?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Sql Server.