WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitive information by reading the PHP session files.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2014-07-29T14:00:00

Updated: 2024-08-06T09:05:39.021Z

Reserved: 2013-12-03T00:00:00

Link: CVE-2014-0103

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2014-07-29T14:55:04.640

Modified: 2015-11-04T17:35:22.093

Link: CVE-2014-0103

cve-icon Redhat

No data.