First published: Tue Aug 12 2014(Updated: )
The Outlook Extension in IBM Content Collector 4.0.0.x before 4.0.0.0-ICC-OE-IF004 allows local users to bypass the intended Reviewer privilege requirement and read e-mail messages from an arbitrary mailbox by invoking the Search function.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Content Collector | =4.0.0.0 | |
IBM Content Collector | =4.0.0.1 | |
IBM Content Collector | =4.0.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4757 is classified as a medium severity vulnerability.
To fix CVE-2014-4757, update IBM Content Collector to version 4.0.0.0-ICC-OE-IF004 or later.
Local users of IBM Content Collector versions 4.0.0.0, 4.0.0.1, or 4.0.0.2 are affected by CVE-2014-4757.
The impact of CVE-2014-4757 allows unauthorized users to bypass privilege restrictions and read e-mail messages from any mailbox.
If the update has not been applied, CVE-2014-4757 remains a risk for systems running vulnerable versions of IBM Content Collector.