Skip to content

[Apiiro] dynatraceable · Critical Risk #4

@ohadr-apiiro

Description

@ohadr-apiiro

Discovered on: Aug 25, 2025 11:58

Finding details
Finding name: IIS app pool creditservice Pool
Severity: Medium
Sources: Dynatrace

About this vulnerability
Description: Affected versions of this package are vulnerable to Unprotected Storage of Credentials. An attacker can steal authentication credentials intended for the database server by performing an adversary-in-the-middle attack between the SQL client and the SQL server, even if the connection is established over an encrypted channel like TLS.
Identifiers:
- CVE-2024-0056

CVSS v3.1.0: 7.5
Exploit maturity: No exploit maturity data

Affected assets
Dependency: System.Data.SqlClient: 4.8.3

View in Apiiro

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions