PT-2018-4267 · Zarafa · Zarafa Collaboration Platform

Publicado

2014-09-22

·

Atualizado

2018-04-20

·

CVE-2014-5450

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zarafa Collaboration Platform version 4.1
Description The issue allows local users to obtain sensitive information by reading license files due to world-readable permissions for /etc/zarafa/license.
Recommendations For Zarafa Collaboration Platform version 4.1, consider changing the permissions of the /etc/zarafa/license file to restrict access and prevent unauthorized reading of sensitive information.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-5450
MGASA-2014-0380

Produtos afetados

Zarafa Collaboration Platform