Insecure default settings in Reporter
By default, logging in to Reporter is performed over HTTP, allowing an attacker to gain access to the Administrator’s credentials and all session data. Disconnected login is also enabled by default thereby storing the Administrator’s LDAP password on Reporter.
All versions of Reporter prior to 9.4 are vulnerable. Windows, Linux, and Virtual Appliance versions are all vulnerable.
Reporter does not default secure when installed with the default configuration values.
By default, administrative connections go over a clear text channel (HTTP) allowing an attacker with access to the network to view, replay, and modify all login and session data.
Disconnected login is also enabled by default in 9.x releases.Disconnected login stores the password used by the Administrator locally with minimal obfuscation. An attacker who is able to de-obfuscate the password will thereby be able to log in to Reporter as the Administrator and will be able to log in to the configured LDAP directory.
Reporter 9.3 and later defaults to HTTPS for administrative connections and redirects HTTP connections to HTTPS. Reporter also disables disconnected login by default.
Configure Reporter to support HTTPS for management connections and always connect to Reporter over HTTPS. Disable disconnected login.
Reporter 9.3 – a fix is available in 18.104.22.168. The fix is available to customers with a valid BlueTouch Online login from https://bto.bluecoat.com/download/product/8793.
Reporter 9.2 and earlier – please upgrade to a later version.
Reporter 8.3 and earlier – please upgrade to a later version.
2012-12-12 Initial public release