VULNERABILITY INTELLIGENCE
CVE-2000-0199
CVSS score7.2 HIGH
EPSS probability1.44%
CISA KEVNot currently listed
Published2000-03-14
Last modified2026-06-16
CVSS vectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Description
When a new SQL Server is registered in Enterprise Manager for Microsoft SQL Server 7.0 and the "Always prompt for login name and password" option is not set, then the Enterprise Manager uses weak encryption to store the login ID and password.
Primary references
- cve@mitre.org — Exploit, Patch, Vendor Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Exploit, Patch, Vendor Advisory