Vulnerability CVE-2013-3273


Published: 2013-07-08   Modified: 2013-07-09

Description:
EMC RSA Authentication Manager 8.0 before P2 and 7.1 before SP4 P26, as used in Appliance 3.0, does not omit the cleartext administrative password from trace logging in custom SDK applications, which allows local users to obtain sensitive information by reading the trace log file.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
RSA Authentication Manager Information Disclosure
RSA
09.07.2013

Type:

CWE-255

(Credentials Management)

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
2.1/10
2.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
RSA -> Authentication manager 

 References:
http://archives.neohapsis.com/archives/bugtraq/2013-07/0046.html

Copyright 2024, cxsecurity.com

 

Back to Top