• caglararli@hotmail.com
  • 05386281520

SQL Server information disclosure non-vulnerability

Çağlar Arlı      -    29 Views

SQL Server information disclosure non-vulnerability

We’ve gotten some questions about a reported issue with SQL Server exposing plaintext user passwords. We investigated the issue and found that attackers would need administrative control of a SQL Server to extract passwords from it. We checked with the security researchers who reported the issue and they confirmed that this is an information disclosure issue requiring the attacker to first have administrative control of the installation.