Lucene search

K
seebugRootSSV:20567
HistoryMay 18, 2011 - 12:00 a.m.

EMC SourceOne产品ASP.NET应用跟踪信息泄露漏洞

2011-05-1800:00:00
Root
www.seebug.org
21

EPSS

0.001

Percentile

49.6%

Bugtraq ID: 47862
CVE ID:CVE-2011-1424

EMC SourceOne Email Management是一款电子邮件管理和监控软件。
启用了ASP.NET应用跟踪的EMC SourceOne Email Management存在安全漏洞,此跟踪文件包含应用程序的敏感信息,远程验证用户可调用ASP.NET应用跟踪从此文件中获得敏感信息。

EMC SourceOne Email Management for Notes/Domino 6.6.0.1209 (HF1)
EMC SourceOne Email Management for Notes/Domino 6.5.2.3668 (SP2 HF3)
EMC SourceOne Email Management for Microsoft Exchange 6.6.0.1209 (HF1)
EMC SourceOne Email Management for Microsoft Exchange 6.5.2.3668 (SP2 HF3
厂商解决方案
EMC SourceOne Email Management 6.6 SP1已经修复此漏洞,建议用户下载使用:
http://www.emc.com/products/launch/sourceone/index.htm

EPSS

0.001

Percentile

49.6%