First published: Thu Nov 12 1998(Updated: )
The installation of 1ArcServe Backup and Inoculan AV client modules for Exchange create a log file, exchverify.log, which contains usernames and passwords in plaintext.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Exchange Server | ||
Broadcom BrightStor ARCserve Backup | ||
Broadcom InoculateIT |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1322 is considered a high severity vulnerability due to the exposure of usernames and passwords in plaintext.
To fix CVE-1999-1322, ensure that the log file exchverify.log is not accessible or remove sensitive information before the log is generated.
CVE-1999-1322 affects Broadcom ArcServe Backup, Broadcom Inoculan anti-virus, and Microsoft Exchange Server installations.
CVE-1999-1322 exposes usernames and passwords in plaintext within the log file exchverify.log.
While CVE-1999-1322 was reported years ago, organizations using the affected software should still be aware of the risk of exposure of sensitive credentials.