First published: Wed Dec 15 2004(Updated: )
The Management Agent in F-Secure Policy Manager 5.11.2810 allows remote attackers to gain sensitive information, such as the absolute path for the web server, via an HTTP request to fsmsh.dll without any parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Withsecure F-Secure Policy Manager | =5.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1223 is considered a medium severity vulnerability due to its potential for information disclosure.
To fix CVE-2004-1223, update to a patched version of F-Secure Policy Manager that addresses this vulnerability.
CVE-2004-1223 can expose sensitive information such as the absolute path of the web server.
CVE-2004-1223 affects users of F-Secure Policy Manager version 5.11.
Yes, CVE-2004-1223 can be exploited remotely via crafted HTTP requests.