CVE-2000-0199
published 2000-03-14CVE-2000-0199: When a new SQL Server is registered in Enterprise Manager for Microsoft SQL Server 7.0 and the "Always prompt for login name and password" option is not set…
PriorityP421high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
1.45%
69.9th percentile
When a new SQL Server is registered in Enterprise Manager for Microsoft SQL Server 7.0 and the "Always prompt for login name and password" option is not set, then the Enterprise Manager uses weak encryption to store the login ID and password.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | sql_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft SQL Server 6.5/7.0 Enterprise Manager missing encryption (Nessus ID 11870 / XFDB-4366)
vuldb·2026-04-21·CVSS 7.2
CVE-2000-0199 [HIGH] Microsoft SQL Server 6.5/7.0 Enterprise Manager missing encryption (Nessus ID 11870 / XFDB-4366)
A vulnerability was found in Microsoft SQL Server 6.5/7.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Enterprise Manager. The manipulation results in missing encryption of sensitive data.
This vulnerability is known as CVE-2000-0199. Attacking locally is a requirement. No exploit is available.
It is suggested to upgrade the affected component.
GHSA
GHSA-5xgx-wrh9-vgf4: When a new SQL Server is registered in Enterprise Manager for Microsoft SQL Server 7
ghsa_unreviewed·2022-04-30
CVE-2000-0199 [HIGH] GHSA-5xgx-wrh9-vgf4: When a new SQL Server is registered in Enterprise Manager for Microsoft SQL Server 7
When a new SQL Server is registered in Enterprise Manager for Microsoft SQL Server 7.0 and the "Always prompt for login name and password" option is not set, then the Enterprise Manager uses weak encryption to store the login ID and password.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2000-03-14
Published