Lucene search

K
cve[email protected]CVE-2014-0103
HistoryJul 29, 2014 - 2:55 p.m.

CVE-2014-0103

2014-07-2914:55:04
CWE-310
web.nvd.nist.gov
28
information security
zarafa
webaccess
webapp
credentials
cleartext
php
session files
apache
cve-2014-0103

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

47.8%

WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitive information by reading the PHP session files.

Affected configurations

NVD
Node
zarafawebappRange1.5
OR
zarafazarafaRange7.1.9
OR
zarafazarafaMatch7.0
OR
zarafazarafaMatch7.0.1
OR
zarafazarafaMatch7.0.2
OR
zarafazarafaMatch7.0.3
OR
zarafazarafaMatch7.0.4
OR
zarafazarafaMatch7.0.5
OR
zarafazarafaMatch7.0.6
OR
zarafazarafaMatch7.0.7
OR
zarafazarafaMatch7.0.8
OR
zarafazarafaMatch7.0.9
OR
zarafazarafaMatch7.0.10
OR
zarafazarafaMatch7.0.11
OR
zarafazarafaMatch7.0.12
OR
zarafazarafaMatch7.0.13
OR
zarafazarafaMatch7.1.0
OR
zarafazarafaMatch7.1.1
OR
zarafazarafaMatch7.1.2
OR
zarafazarafaMatch7.1.3
OR
zarafazarafaMatch7.1.4
OR
zarafazarafaMatch7.1.8
OR
fedoraprojectfedoraMatch19
OR
fedoraprojectfedoraMatch20

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

47.8%