CVE-2007-3581
Status: ModifiedMedium (5)—
The Jedox Palo 1.5 client transmits the password in cleartext, which might allow remote attackers to obtain the password by sniffing the network, as demonstrated by starting Excel with the Palo plugin, opening a cube, and performing an Insert View.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N
- Base score: 5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.57%
- Percentile among all scored CVEs: 75
- Score date: 10/3/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- NVD-CWE-Other
References
Raw JSON (NVD)
Show
{
"id": "CVE-2007-3581",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-07-05T20:30:00.000",
"references": [
{
"url": "http://85.10.222.122/mantis/public_show_bug.php?bug_id=452",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/45754",
"source": "cve@mitre.org"
},
{
"url": "http://85.10.222.122/mantis/public_show_bug.php?bug_id=452",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/45754",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Jedox Palo 1.5 client transmits the password in cleartext, which might allow remote attackers to obtain the password by sniffing the network, as demonstrated by starting Excel with the Palo plugin, opening a cube, and performing an Insert View."
},
{
"lang": "es",
"value": "El cliente Jedox Palo 1.5 transmite la contraseña en texto claro, lo cual podría permitir a usuarios remotos obtener la contraseña husmeando la red, como se ha demostrado iniciando Excel con la extensión Palo, abriendo un cubo, y realizando una acción Insertar Vista."
}
],
"lastModified": "2026-06-16T22:42:19.450",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:jedox:palo:1.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "65834E52-0076-43A1-B859-B001DBC4BF34"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}