First published: Fri Feb 07 2014(Updated: )
The Web Email Protection component in Symantec Encryption Management Server (aka PGP Universal Server) before 3.3.2 allows remote authenticated users to read the stored outbound e-mail messages of arbitrary users via a modified URL.
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Encryption Management Server | <=3.3.1 | |
Symantec Encryption Management Server | =3.3.0 | |
Symantec Encryption Management Server | =3.3.0-mp1 | |
Symantec Encryption Management Server | =3.3.0-mp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1643 is classified as a high severity vulnerability.
To fix CVE-2014-1643, upgrade your Symantec Encryption Management Server to version 3.3.2 or later.
CVE-2014-1643 allows authenticated remote users to access stored outbound email messages of other users.
CVE-2014-1643 affects versions 3.3.1 and earlier of Symantec Encryption Management Server.
CVE-2014-1643 cannot be exploited by unauthenticated users as it requires valid authentication credentials.