The Frontend component in Sophos UTM with firmware 9.405-5 and earlier allows local administrators to obtain sensitive password information by reading the "value" field of the proxy user settings in "system settings / scan settings / anti spam" configuration tab.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1036931 | vdb entry |
http://www.securityfocus.com/bid/93266 | vdb entry |
http://www.securityfocus.com/archive/1/539518/100/0/threaded | mailing list |