CVE-2011-2736: Medium severity rsa envision vulnerability
Published Aug 25, 2011
·Updated
RSA enVision 4.x before 4 SP4 P3 places cleartext administrative credentials in Task Escalation e-mail messages, which allows remote attackers to obtain sensitive information by sniffing the network or leveraging access to a recipient mailbox.
Affected Software
3 affected components
RSA EnVision=4.0-sp3
RSA EnVision=4.0-sp2
RSA EnVision=4.0-sp1
Event History
Aug 25, 2011
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-2736?
CVE-2011-2736 is considered a medium severity vulnerability due to the exposure of sensitive credentials.
2
How do I fix CVE-2011-2736?
To fix CVE-2011-2736, upgrade to RSA enVision version 4 SP4 P3 or later.
3
What type of information is exposed in CVE-2011-2736?
CVE-2011-2736 exposes cleartext administrative credentials in email messages.
4
Who is affected by CVE-2011-2736?
CVE-2011-2736 affects users running RSA enVision versions 4.0 SP1, SP2, or SP3.
5
Can CVE-2011-2736 be exploited remotely?
Yes, CVE-2011-2736 can be exploited remotely if an attacker has access to sniff the network or a recipient mailbox.