First published: Sat Feb 14 2015(Updated: )
The InputAccel Database (IADB) installation process in EMC Captiva Capture 7.0 before patch 25 and 7.1 before patch 13 places a cleartext InputAccel (IA) SQL password in a DAL log file, which allows local users to obtain sensitive information by reading a file.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC Captiva Capture | =7.0 | |
EMC Captiva Capture | =7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0519 is considered to have a medium severity due to the potential exposure of sensitive information.
To fix CVE-2015-0519, apply the latest patches for EMC Captiva Capture, specifically patch 25 for version 7.0 or patch 13 for version 7.1.
CVE-2015-0519 addresses a sensitive information disclosure vulnerability where cleartext SQL passwords are logged in a DAL file.
CVE-2015-0519 affects users of EMC Captiva Capture versions 7.0 prior to patch 25 and 7.1 prior to patch 13.
Yes, local users can exploit CVE-2015-0519 to obtain sensitive SQL password information by reading the affected DAL log file.