CVE-2015-9278: Critical severity tenable.io vulnerability
Published Jan 16, 2019
·Updated
MailEnable before 8.60 allows Privilege Escalation because admin accounts could be created as a consequence of %0A mishandling in AUTH.TAB after a password-change request.
Affected Software
1 affected component
MailEnable MailEnable<8.60
Event History
Jan 16, 2019
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-9278?
CVE-2015-9278 has been classified as a moderate severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2015-9278?
To fix CVE-2015-9278, update MailEnable to version 8.60 or later.
3
What kind of vulnerability is CVE-2015-9278?
CVE-2015-9278 is a privilege escalation vulnerability impacting MailEnable.
4
What are the consequences of CVE-2015-9278?
The consequences of CVE-2015-9278 include the unauthorized creation of admin accounts.
5
Which versions of MailEnable are affected by CVE-2015-9278?
MailEnable versions prior to 8.60 are affected by CVE-2015-9278.