A security weakness in the LexisNexis Concordance litigation support system could allow people to hijack database passwords, putting attorneys’ client data at risk of theft, according to the hacker who discovered it. Concordance helps legal professionals import and manage trial documents, search and annotate data, and create custom case reports.

There have not been documented attacks based on the weakness, which is easily prevented if customers follow Lexis’ advice to lock their databases. But many customers do not, and are left with Concordance running in its default, unlocked configuration.