First published: Thu Jan 19 2012(Updated: )
The Web Search feature in EMC SourceOne Email Management 6.5 before 6.5.2.4033, 6.6 before 6.6.1.2194, and 6.7 before 6.7.2.2033 places cleartext credentials in log files, which allows local users to obtain sensitive information by reading these files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC SourceOne | <=6.6.1.2108 | |
Dell EMC SourceOne | =6.7 | |
Dell EMC SourceOne | =6.6 | |
Dell EMC SourceOne | <=6.5.2.3668 | |
Dell EMC SourceOne | =6.5 | |
Dell EMC SourceOne | =6.6.0.1209 | |
Dell EMC SourceOne | <=6.7.2.0017 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4142 is classified with a medium severity due to the exposure of sensitive credentials.
To fix CVE-2011-4142, upgrade EMC SourceOne Email Management to version 6.5.2.4033, 6.6.1.2194, or 6.7.2.2033 or later.
CVE-2011-4142 affects EMC SourceOne Email Management versions prior to 6.5.2.4033, 6.6.1.2194, and 6.7.2.2033.
CVE-2011-4142 exposes cleartext credentials in log files that can be accessed by local users.
CVE-2011-4142 cannot be exploited remotely as it requires local access to the log files.