PT-2014-5806 · Epicor · Epicor Enterprise
Fara Rustein
·
Published
2014-11-04
·
Updated
2014-11-05
·
CVE-2014-4311
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Epicor Enterprise version 7.4 before FS74SP6 HotfixTL054181
Description
The issue allows attackers to obtain sensitive information, including the database connection and email connection passwords, by reading the HTML source code of the database connection and email settings page.
Recommendations
For Epicor Enterprise version 7.4 before FS74SP6 HotfixTL054181, apply the FS74SP6 HotfixTL054181 patch to resolve the issue.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Epicor Enterprise