Best Practical Solutions Request Tracker
cpe:2.3:a:bestpractical:request_tracker:*:*:*:*:*:*:*
- < 5.0.8
A vulnerability exists in Best Practical Solutions, LLC's Request Tracker in versions prior to 5.0.8, where the outdated Triple DES (3DES) algorithm is used to encrypt emails with S/MIME. This reliance on 3DES, which is vulnerable to birthday attacks, compromises the confidentiality of the encrypted messages.
The use of Triple DES for S/MIME encryption is outdated and insecure, allowing for potential birthday attacks that could compromise the confidentiality of encrypted emails.
Users can upgrade to Request Tracker version 5.0.8, where this vulnerability has been addressed. Instructions for downloading this version are available in the release notes.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.