PT-2011-3120 · Emc · Emc Sourceone Email Management

Published

2011-05-24

·

Updated

2018-10-09

·

CVE-2011-1424

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions EMC SourceOne Email Management versions prior to 6.6 SP1
Description The issue arises from the default configuration of ExShortcutWeb.config in EMC SourceOne Email Management, specifically when the Mobile Services component is utilized. The localOnly attribute of the trace element is not properly set, allowing remote authenticated users to obtain sensitive information via ASP.NET Application Tracing.
Recommendations For versions prior to 6.6 SP1, update to version 6.6 SP1 or later to resolve the issue. As a temporary workaround, consider setting the localOnly attribute of the trace element to true in the ExShortcutWeb.config file to restrict access to ASP.NET Application Tracing.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-1424

Affected Products

Emc Sourceone Email Management