SB2018073106 - Information disclosure in EMC NetWorker
Published: July 31, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2018-11050)
The vulnerability allows an adjacent attacker to obtain potentially sensitive information.
The vulnerability exists due to a flaw in the Rabbit MQ Advanced Message Queuing Protocol (AMQP) component. A remote attacker monitoring the local network collision domain can obtain clear text passwords that are sent to the remote AMQP service and access the target component with the privileges of the target user.
Remediation
Install update from vendor's website.