LOW · 3.5

CVE-2011-1424

The default configuration of ExShortcut\Web.config in EMC SourceOne Email Management before 6.6 SP1, when the Mobile Services component is used, does not properly set the localOnly attribute of the tr...

Vulnerability Description

The default configuration of ExShortcut\Web.config in EMC SourceOne Email Management before 6.6 SP1, when the Mobile Services component is used, does not properly set the localOnly attribute of the trace element, which allows remote authenticated users to obtain sensitive information via ASP.NET Application Tracing.

CVSS Score

3.5

LOW

AV:N/AC:M/Au:S/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
EmcSourceone Email Management<= 6.6.0.1209
MicrosoftExchangeAll versions
IbmLotus DominoAll versions
IbmLotus NotesAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-1424?

CVE-2011-1424 is a vulnerability with a CVSS score of 3.5 (LOW). The default configuration of ExShortcut\Web.config in EMC SourceOne Email Management before 6.6 SP1, when the Mobile Services component is used, does not properly set the localOnly attribute of the tr...

How severe is CVE-2011-1424?

CVE-2011-1424 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-1424?

Check the references section above for vendor advisories and patch information. Affected products include: Emc Sourceone Email Management, Microsoft Exchange, Ibm Lotus Domino, Ibm Lotus Notes.