Information disclosure - CVE-2016-7397

 

Information disclosure - CVE-2016-7397

Published: September 30, 2016 / Updated: October 3, 2016


Vulnerability identifier: #VU695
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2016-7397
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor:
Affected software:

Detailed vulnerability description

The vulnerability allows a remote authenticated adminiatrative user to disclose passwords on the target system.
The weakness exists  due to acess control error. A malicious user can obtain the SMTP password in the 'value' field of the SMTP user settings notification tab.
Successful exploitation of the vulnerability may result in certain passwords disclosure.

How to mitigate CVE-2016-7397

No solution resolving the vulnerability is available.

Sources