Bugtraq ID: 47862
CVE ID:CVE-2011-1424
EMC SourceOne Email Management是一款电子邮件管理和监控软件。
启用了ASP.NET应用跟踪的EMC SourceOne Email Management存在安全漏洞,此跟踪文件包含应用程序的敏感信息,远程验证用户可调用ASP.NET应用跟踪从此文件中获得敏感信息。
EMC SourceOne Email Management for Notes/Domino 6.6.0.1209 (HF1)
EMC SourceOne Email Management for Notes/Domino 6.5.2.3668 (SP2 HF3)
EMC SourceOne Email Management for Microsoft Exchange 6.6.0.1209 (HF1)
EMC SourceOne Email Management for Microsoft Exchange 6.5.2.3668 (SP2 HF3
厂商解决方案
EMC SourceOne Email Management 6.6 SP1已经修复此漏洞,建议用户下载使用:
http://www.emc.com/products/launch/sourceone/index.htm