MAIN MENU

Security & compliance

Upholding the highest standards to protect your data and ensure trust.

DEVO-2022-0008

Database connections are not closed properly on MySQL data sources after a user is deleted which could allow them to access unauthorized data.

Affected Products

Remote Desktop Manager
2022.3.7 and earlier.

Change Log

Initial publication - 2022-11-01

Database connections for deleted users not closed on MySQL data sources

Medium - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Database connections on deleted users could stay active on MySQL data sources in Remote Desktop Manager 2022.3.7 and below which allow deleted users to access unauthorized data.

CVE(s)

CVE-2022-3780

Remediation and Workarounds

Upgrade to Remote Desktop Manager 2022.3.8 and later.