MidnightBSD

Advisories for thycotic

CVE-2014-4861 HIGH

The Remote Desktop Launcher in Thycotic Secret Server before 8.6.000010 does not properly cleanup a temporary file that contains an encrypted password once a session has ended.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-255,

Products Affected

Vendor Product Version
thycotic secret_server *
CVE-2015-3443 LOW

Cross-site scripting (XSS) vulnerability in the basic dashboard in Thycotic Secret Server 8.6.x, 8.7.x, and 8.8.x before 8.8.000005 allows remote authenticated users to inject arbitrary web script or HTML via a password entry, which is not properly handled when toggling the password mask.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
thycotic secret_server 8.6.000000
thycotic secret_server 8.7.000000
thycotic secret_server 8.6.000009
thycotic secret_server 8.8.000004
thycotic secret_server 8.8.000001
thycotic secret_server 8.6.000010
thycotic secret_server 8.8.000000
CVE-2015-4094 MEDIUM

The Thycotic Password Manager Secret Server application through 2.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-295,

Products Affected

Vendor Product Version
thycotic secret_server *
CVE-2017-11725 MEDIUM

The share function in Thycotic Secret Server before 10.2.000019 mishandles the Back Button, leading to unintended redirections.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
thycotic secret_server *