PT-2014-5806 · Epicor · Epicor Enterprise

Fara Rustein

·

Published

2014-11-04

·

Updated

2014-11-05

·

CVE-2014-4311

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Epicor Enterprise version 7.4 before FS74SP6 HotfixTL054181
Description The issue allows attackers to obtain sensitive information, including the database connection and email connection passwords, by reading the HTML source code of the database connection and email settings page.
Recommendations For Epicor Enterprise version 7.4 before FS74SP6 HotfixTL054181, apply the FS74SP6 HotfixTL054181 patch to resolve the issue.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-4311

Affected Products

Epicor Enterprise