CVE-2015-4547: Infoleak
Published Oct 12, 2015
·Updated
EMC RSA Web Threat Detection before 5.1 SP1 stores a cleartext AnnoDB password in a configuration file, which allows remote authenticated users to obtain sensitive information by reading this file.
Affected Software
1 affected component
RSA Web Threat Detection<=5.1
Event History
Oct 12, 2015
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4547?
CVE-2015-4547 is rated as a medium severity vulnerability due to the exposure of sensitive information.
2
How do I fix CVE-2015-4547?
To fix CVE-2015-4547, upgrade to RSA Web Threat Detection version 5.1 SP1 or later.
3
What type of information is exposed in CVE-2015-4547?
CVE-2015-4547 exposes the database connection password stored in cleartext in a configuration file.
4
Who is affected by CVE-2015-4547?
Users of EMC RSA Web Threat Detection versions prior to 5.1 SP1 are affected by CVE-2015-4547.
5
Can CVE-2015-4547 be exploited remotely?
Yes, CVE-2015-4547 can be exploited by remote authenticated users who can read the configuration file.