Information disclosure - CVE-2016-7442
Published: October 3, 2016
Vulnerability identifier: #VU696
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2016-7442
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor:
Affected software:
Detailed vulnerability description
The vulnerability allows a remote authenticated adminiatrative user to disclose passwords on the target system.
The weakness exists due to acess control error. A malicious user can obtain the proxy password in the 'value' field of the proxy user settings page..
Successful exploitation of the vulnerability may result in certain passwords disclosure.
The weakness exists due to acess control error. A malicious user can obtain the proxy password in the 'value' field of the proxy user settings page..
Successful exploitation of the vulnerability may result in certain passwords disclosure.
How to mitigate CVE-2016-7442
No solution resolving the vulnerability is available.