PT-2012-1811 · Emc · Emc Sourceone Email Management
Published
2012-01-19
·
Updated
2012-01-19
·
CVE-2011-4142
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
EMC SourceOne Email Management versions 6.5 through 6.5.2.4033
EMC SourceOne Email Management versions 6.6 through 6.6.1.2194
EMC SourceOne Email Management versions 6.7 through 6.7.2.2033
Description
The issue concerns the Web Search feature, which stores cleartext credentials in log files. This allows local users to access sensitive information by reading these files.
Recommendations
For versions 6.5 through 6.5.2.4033, update to version 6.5.2.4033 or later.
For versions 6.6 through 6.6.1.2194, update to version 6.6.1.2194 or later.
For versions 6.7 through 6.7.2.2033, update to version 6.7.2.2033 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Emc Sourceone Email Management