CVE-2018-17287: Medium severity kofax front office server vulnerability
In Kofax Front Office Server Administration Console 4.1.1.11.0.5212, some fields, such as passwords, are obfuscated in the front-end, but the cleartext value can be exfiltrated by using the back-end "download" feature, as demonstrated by an mfp.password downloadsettingvalue operation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-17287?
CVE-2018-17287 is classified as a medium severity vulnerability due to the potential for information disclosure.
How does CVE-2018-17287 affect Kofax Front Office Server?
CVE-2018-17287 allows attackers to exfiltrate cleartext password values through the back-end download feature.
How can I fix CVE-2018-17287?
To mitigate CVE-2018-17287, update Kofax Front Office Server to a version that addresses this vulnerability.
What are the potential impacts of CVE-2018-17287?
CVE-2018-17287 can lead to unauthorized access to sensitive information, compromising user credentials.
Is CVE-2018-17287 present in other versions of Kofax Front Office Server?
CVE-2018-17287 specifically affects version 4.1.1.11.0.5212 of Kofax Front Office Server.