VYPR
Medium severity5.5NVD Advisory· Published Oct 23, 2007· Updated Apr 23, 2026

CVE-2007-5626

CVE-2007-5626

Description

make_catalog_backup in Bacula 2.2.5, and probably earlier, sends a MySQL password as a command line argument, and sometimes transmits cleartext e-mail containing this command line, which allows context-dependent attackers to obtain the password by listing the process and its arguments, or by sniffing the network.

Affected products

1
  • cpe:2.3:a:bacula:bacula:*:*:*:*:*:*:*:*
    Range: <=2.2.5

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

9

News mentions

0

No linked articles in our index yet.