Lucene search

K
cveDellCVE-2011-1424
HistoryMay 24, 2011 - 11:55 p.m.

CVE-2011-1424

2011-05-2423:55:02
CWE-16
dell
web.nvd.nist.gov
25
cve-2011-1424
exshortcut
emc sourceone email management
asp.net application tracing
information security
vulnerability

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

AI Score

5.9

Confidence

Low

EPSS

0.001

Percentile

49.6%

The default configuration of ExShortcut\Web.config in EMC SourceOne Email Management before 6.6 SP1, when the Mobile Services component is used, does not properly set the localOnly attribute of the trace element, which allows remote authenticated users to obtain sensitive information via ASP.NET Application Tracing.

Affected configurations

Nvd
Node
emcsourceone_email_managementRange6.6.0.1209
OR
emcsourceone_email_managementMatch6.5.2.3668
AND
microsoftexchange
Node
emcsourceone_email_managementRange6.6.0.1209
OR
emcsourceone_email_managementMatch6.5.2.3668
AND
ibmlotus_domino
OR
ibmlotus_notes
VendorProductVersionCPE
emcsourceone_email_management*cpe:2.3:a:emc:sourceone_email_management:*:*:*:*:*:*:*:*
emcsourceone_email_management6.5.2.3668cpe:2.3:a:emc:sourceone_email_management:6.5.2.3668:*:*:*:*:*:*:*
microsoftexchange*cpe:2.3:a:microsoft:exchange:*:*:*:*:*:*:*:*
ibmlotus_domino*cpe:2.3:a:ibm:lotus_domino:*:*:*:*:*:*:*:*
ibmlotus_notes*cpe:2.3:a:ibm:lotus_notes:*:*:*:*:*:*:*:*

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

AI Score

5.9

Confidence

Low

EPSS

0.001

Percentile

49.6%