Vulnerability Description
The default configuration of ExShortcut\Web.config in EMC SourceOne Email Management before 6.6 SP1, when the Mobile Services component is used, does not properly set the localOnly attribute of the trace element, which allows remote authenticated users to obtain sensitive information via ASP.NET Application Tracing.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Emc | Sourceone Email Management | <= 6.6.0.1209 |
| Microsoft | Exchange | All versions |
| Ibm | Lotus Domino | All versions |
| Ibm | Lotus Notes | All versions |
Related Weaknesses (CWE)
References
- http://securityreason.com/securityalert/8258
- http://www.securityfocus.com/archive/1/518003/100/0/threaded
- http://securityreason.com/securityalert/8258
- http://www.securityfocus.com/archive/1/518003/100/0/threaded
FAQ
What is CVE-2011-1424?
CVE-2011-1424 is a vulnerability with a CVSS score of 3.5 (LOW). The default configuration of ExShortcut\Web.config in EMC SourceOne Email Management before 6.6 SP1, when the Mobile Services component is used, does not properly set the localOnly attribute of the tr...
How severe is CVE-2011-1424?
CVE-2011-1424 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-1424?
Check the references section above for vendor advisories and patch information. Affected products include: Emc Sourceone Email Management, Microsoft Exchange, Ibm Lotus Domino, Ibm Lotus Notes.