Guest

Preview Tool

Cisco Bug: CSCus80686 - FTP password of TCE profile is reflected as clear text in Logs and DB.

Last Modified

Dec 25, 2016

Products (1)

  • Cisco ASR 5000 Series

Known Affected Releases

16.4.0

Description (partial)

Symptom:
FTP password of TCE profile is reflected as clear text in query.log_intracer and postgress DB. As password is a confidential element so it should not reflect anywhere as clear text.

Note : on Intracer GUI the password field is not readable.Character are converted into black dots.

Conditions:
Reproduce Step:
1. Login to InTracer UI and navigate to Configure -->R-TCE --> New
2. Fill all mandatory fields and add the R-TCE server by clicking the save button.
3. See the out put of tail -f [C-Intreacer-HomePath]/webgateway/query/logs/query.log_intracer.
4. Login to postgress database , run the query " select * from lte_traceprofileinfo;" and verify the password field.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.