The vendor explicitly identifies these products as affected by this CVE.
- Spectrum Power 4
- Summary
- The affected application is vulnerable to extraction of database credentials via a world-readable credential file. This allows an attacker to connect to the database as privileged application user and to run system commands via the database.
- Remediation
- Update to V4.70 SP12 Update 2 or later version
