Information disclosure in RSA Data Loss Prevention - CVE-2016-0893

 

Information disclosure in RSA Data Loss Prevention - CVE-2016-0893

Published: May 3, 2016 / Updated: August 9, 2020


Vulnerability identifier: #VU40322
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2016-0893
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Dell
Affected software:
RSA Data Loss Prevention

Detailed vulnerability description

The vulnerability allows a remote authenticated user to gain access to sensitive information.

EMC RSA Data Loss Prevention 9.6 before SP2 P5 allows remote authenticated users to obtain sensitive information by reading error messages.


How to mitigate CVE-2016-0893

Install update from vendor's website.

Sources