First published: Thu Oct 18 2012(Updated: )
The (1) install and (2) upgrade processes in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 375, when Exchange Server is used, allow local users to read cleartext administrator credentials via unspecified vectors.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC NetWorker Module for Microsoft Applications | =2.2.1 | |
EMC NetWorker Module for Microsoft Applications | =2.3 | |
EMC NetWorker Module for Microsoft Applications | =2.4 | |
Microsoft Exchange Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2284 is classified as a vulnerability that allows local users to read cleartext administrator credentials, indicating a high severity risk.
To fix CVE-2012-2284, upgrade to EMC NetWorker Module for Microsoft Applications version 2.4 build 375 or higher.
CVE-2012-2284 affects EMC NetWorker Module for Microsoft Applications versions 2.2.1, 2.3 before build 122, and 2.4 before build 375.
CVE-2012-2284 cannot be exploited remotely as it involves local user access to the affected system.
CVE-2012-2284 impacts local user accounts that have access to the EMC NetWorker Module under specific configurations.