Rapid7 Vulnerability & Exploit Database

TDS (SQL Server) access with username sa and password sa

Back to Search

TDS (SQL Server) access with username sa and password sa

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
01/30/2009
Created
07/25/2018
Added
01/30/2009
Modified
12/04/2013

Description

TDS servers such as Microsoft SQL Server and Sybase create a default administrative account with the user ID "sa" and password "sa". It is best practice to remove default accounts, if possible. For accounts required by the system, the default password should be changed. This account often grants full access to the system.

Solution(s)

  • fix-tds-default-account-sa-sa

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;