TransWARE Active! mail 6, when an external public interface is used, allows local users to obtain sensitive information belonging to arbitrary users by leveraging shell access, as demonstrated by a TELNET or SSH session to the server.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://jvn.jp/en/jp/JVN04288738/458182/index.html | |
http://jvndb.jvn.jp/jvndb/JVNDB-2013-000031 | third party advisory |
http://jvn.jp/en/jp/JVN04288738/index.html | third party advisory |