CVE-2018-7704: Infoleak
Published Mar 14, 2018
·Updated
SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read arbitrary e-mail messages via the option1 parameter in a reply action to secmail/getmessage.exe.
Affected Software
1 affected component
SecurEnvoy SecurMail<9.2.501
Event History
Mar 14, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Mar 15, 2018
Data Sourced
via NVD·01:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-7704?
CVE-2018-7704 is classified as a medium severity vulnerability.
2
How do I fix CVE-2018-7704?
To fix CVE-2018-7704, upgrade SecurEnvoy SecurMail to version 9.2.501 or later.
3
What type of vulnerability is CVE-2018-7704?
CVE-2018-7704 is a remote code execution vulnerability affecting SecurEnvoy SecurMail.
4
Who is affected by CVE-2018-7704?
Remote authenticated users of SecurEnvoy SecurMail versions before 9.2.501 are affected by CVE-2018-7704.
5
What can attackers do with CVE-2018-7704?
Attackers exploiting CVE-2018-7704 can read arbitrary e-mail messages by manipulating the option1 parameter.