WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitive information by reading the PHP session files.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2014-07-29T14:00:00

Updated: 2014-10-31T13:57:00

Reserved: 2013-12-03T00:00:00


Link: CVE-2014-0103

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2014-07-29T14:55:04.640

Modified: 2015-11-04T17:35:22.093


Link: CVE-2014-0103

JSON object: View

cve-icon Redhat Information

No data.

CWE