Information disclosure - CVE-2016-7442

 

Information disclosure - CVE-2016-7442

Published: October 3, 2016


Vulnerability identifier: #VU696
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2016-7442
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor:
Affected software:

Detailed vulnerability description

The vulnerability allows a remote authenticated adminiatrative user to disclose passwords on the target system.
The weakness exists  due to acess control error. A malicious user can obtain the proxy password in the 'value' field of the proxy user settings page..
Successful exploitation of the vulnerability may result in certain passwords disclosure.

How to mitigate CVE-2016-7442

No solution resolving the vulnerability is available.

Sources