PT-2018-4267 · Zarafa · Zarafa Collaboration Platform

Published

2014-09-22

·

Updated

2018-04-20

·

CVE-2014-5450

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zarafa Collaboration Platform version 4.1
Description The issue allows local users to obtain sensitive information by reading license files due to world-readable permissions for /etc/zarafa/license.
Recommendations For Zarafa Collaboration Platform version 4.1, consider changing the permissions of the /etc/zarafa/license file to restrict access and prevent unauthorized reading of sensitive information.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-5450
MGASA-2014-0380

Affected Products

Zarafa Collaboration Platform