Lucene search

K
cveMicrofocusCVE-2021-38130
HistoryFeb 04, 2022 - 11:15 p.m.

CVE-2021-38130

2022-02-0423:15:11
microfocus
web.nvd.nist.gov
33
cve-2021-38130
information leakage
vulnerability
micro focus
securemail
nvd

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

28.4%

A potential Information leakage vulnerability has been identified in versions of Micro Focus Voltage SecureMail Mail Relay prior to 7.3.0.1. The vulnerability could be exploited to create an information leakage attack.

Affected configurations

Nvd
Node
microfocusvoltage_securemailRange<7.3.0.1
VendorProductVersionCPE
microfocusvoltage_securemail*cpe:2.3:a:microfocus:voltage_securemail:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Voltage SecureMail Mail Relay.",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "All version prior to 7.3.0.1"
      }
    ]
  }
]

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

28.4%

Related for CVE-2021-38130