CVE-1999-1322: Medium severity Microsoft Exchange Server vulnerability
The installation of 1ArcServe Backup and Inoculan AV client modules for Exchange create a log file, exchverify.log, which contains usernames and passwords in plaintext.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Broadcom BrightStor ARCserve Backupfrom your environment.Uninstall the ArcServe Backup Exchange client module (if not required). The installation creates exchverify.log which contains usernames and passwords in plaintext.
- Remove
Remove
Broadcom InoculateITfrom your environment.Uninstall the InoculateIT Exchange AV client module (if not required). The installation creates exchverify.log which contains usernames and passwords in plaintext.
- Compensating control
Restrict access to exchverify.log using filesystem ACLs and limit access to trusted administrators only; monitor and alert on access to the file until the issue is remediated.
- Operational
Locate all instances of exchverify.log on affected systems and securely delete or wipe the files and any backups that contain them.
- Operational
Rotate any usernames and passwords that may have been exposed in exchverify.log (change affected Exchange account credentials and any associated service credentials) before returning systems to normal operation.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1322?
CVE-1999-1322 is considered a high severity vulnerability due to the exposure of usernames and passwords in plaintext.
How do I fix CVE-1999-1322?
To fix CVE-1999-1322, ensure that the log file exchverify.log is not accessible or remove sensitive information before the log is generated.
What software is affected by CVE-1999-1322?
CVE-1999-1322 affects Broadcom ArcServe Backup, Broadcom Inoculan anti-virus, and Microsoft Exchange Server installations.
What type of information is exposed in CVE-1999-1322?
CVE-1999-1322 exposes usernames and passwords in plaintext within the log file exchverify.log.
Is CVE-1999-1322 still a concern today?
While CVE-1999-1322 was reported years ago, organizations using the affected software should still be aware of the risk of exposure of sensitive credentials.