Vulnerability Description
SalesLogix 6.1 includes usernames, passwords, and other sensitive information in the headers of an HTTP response, which could allow remote attackers to gain access.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Best Software | Saleslogix | All versions |
| Saleslogix Corporation | Saleslogix | 2000.0 |
References
- http://archives.neohapsis.com/archives/fulldisclosure/2004-10/0661.html
- http://marc.info/?l=bugtraq&m=109811852218478&w=2
- http://secunia.com/advisories/12883PatchVendor Advisory
- http://securitytracker.com/id?1011769
- http://www.osvdb.org/10946
- http://www.securityfocus.com/bid/11450ExploitPatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17753
- http://archives.neohapsis.com/archives/fulldisclosure/2004-10/0661.html
- http://marc.info/?l=bugtraq&m=109811852218478&w=2
- http://secunia.com/advisories/12883PatchVendor Advisory
- http://securitytracker.com/id?1011769
- http://www.osvdb.org/10946
- http://www.securityfocus.com/bid/11450ExploitPatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17753
FAQ
What is CVE-2004-1609?
CVE-2004-1609 is a vulnerability with a CVSS score of 5.0 (MEDIUM). SalesLogix 6.1 includes usernames, passwords, and other sensitive information in the headers of an HTTP response, which could allow remote attackers to gain access.
How severe is CVE-2004-1609?
CVE-2004-1609 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-1609?
Check the references section above for vendor advisories and patch information. Affected products include: Best Software Saleslogix, Saleslogix Corporation Saleslogix.