In Delinea PAM Secret Server 11.4, it is possible for an attacker (with Administrator access to the Secret Server machine) to read the following data from a memory dump: the decrypted master key, database credentials (when SQL Server Authentication is enabled), the encryption key of RabbitMQ queue messages, and session cookies.
| Software | From | Fixed in |
|---|---|---|
| delinea / secret_server | 11.4.000000 | 11.4.000000.x |