First published: Mon Jul 08 2013(Updated: )
EMC Replication Manager (RM) before 5.4.4 places encoded passwords in application log files, which makes it easier for local users to obtain sensitive information by reading a file and conducting an unspecified decoding attack.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC Replication Manager | <=5.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2013-3272 is considered medium due to the risk of sensitive information disclosure.
To fix CVE-2013-3272, upgrade EMC Replication Manager to version 5.4.4 or later.
CVE-2013-3272 involves sensitive information disclosure due to improper password handling in log files.
Users of EMC Replication Manager versions prior to 5.4.4 are affected by CVE-2013-3272.
Attackers with local access can potentially decode encoded passwords from application log files as a result of CVE-2013-3272.