First published: Fri Sep 18 2015(Updated: )
The Secondary server in Threat Intelligence Exchange (TIE) before 1.2.0 uses weak permissions for unspecified (1) configuration files and (2) installation logs, which allows local users to obtain sensitive information by reading the files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mcafee Threat Intelligence Exchange | <=1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7238 is classified as a medium severity vulnerability.
To mitigate CVE-2015-7238, update the Threat Intelligence Exchange to version 1.2.0 or later.
CVE-2015-7238 affects McAfee Threat Intelligence Exchange versions prior to 1.2.0.
CVE-2015-7238 allows local users to read sensitive configuration files and installation logs.
Local users with access to the Secondary server in Threat Intelligence Exchange can exploit CVE-2015-7238.