Security & compliance
Upholding the highest standards to protect your data and ensure trust.
DEVO-2022-0008
Database connections are not closed properly on MySQL data sources after a user is deleted which could allow them to access unauthorized data.
Affected Products
Change Log
Initial publication - 2022-11-01
Database connections for deleted users not closed on MySQL data sources
Medium - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Database connections on deleted users could stay active on MySQL data sources in Remote Desktop Manager 2022.3.7 and below which allow deleted users to access unauthorized data.
CVE(s)
CVE-2022-3780
Remediation and Workarounds
Upgrade to Remote Desktop Manager 2022.3.8 and later.