SB2018073106 - Information disclosure in EMC NetWorker



SB2018073106 - Information disclosure in EMC NetWorker

Published: July 31, 2018

Security Bulletin ID SB2018073106
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Adjecent network
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Information disclosure (CVE-ID: CVE-2018-11050)

The vulnerability allows an adjacent attacker to obtain potentially sensitive information.

The vulnerability exists due to a flaw in the Rabbit MQ Advanced Message Queuing Protocol (AMQP) component. A remote attacker monitoring the local network collision domain can obtain clear text passwords that are sent to the remote AMQP service and access the target component with the privileges of the target user.


Remediation

Install update from vendor's website.