First published: Mon Oct 12 2015(Updated: )
EMC RSA Web Threat Detection before 5.1 SP1 stores a cleartext AnnoDB password in a configuration file, which allows remote authenticated users to obtain sensitive information by reading this file.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
RSA Web Threat Detection | <=5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4547 is rated as a medium severity vulnerability due to the exposure of sensitive information.
To fix CVE-2015-4547, upgrade to RSA Web Threat Detection version 5.1 SP1 or later.
CVE-2015-4547 exposes the database connection password stored in cleartext in a configuration file.
Users of EMC RSA Web Threat Detection versions prior to 5.1 SP1 are affected by CVE-2015-4547.
Yes, CVE-2015-4547 can be exploited by remote authenticated users who can read the configuration file.