Sign In
Forgot Password

Don’t have an account? Create One.

NetBackup Appliance 3.1.2+ HotFix - Passwords appear in console (article 100045024)

HotFix

Abstract

Preventing passwords from appearing in the NetBackup Appliance Web Console

Description

Passwords can appear in clear text on screen in the NetBackup Appliance Web Console (web console) after the following sequence of events:

  1. Set and save the settings on the Alerts & Notifications page, either during the initial configuration or when making changes afterwards.
  2. Navigate back to the Alerts & Notifications page, but then access the "Web Developer console" in Firefox.

This problem exists in all NetBackup Appliance software versions from 2.7.3 to 3.1.2.

Note: This issue does not exist on the NetBackup Appliance Shell Menu interfaces.


Cause

The settings flow for SMTP and Callhome Proxy do not mask the passwords in the HTML code. Even though the passwords are masked in the data input fields, the HTML code can be exploited by a user that can log in to the web console and does not have authorization to the SMTP and Proxy credentials.

Applies to the following product releases

Update files

File name Description Version Platform Size