LOW · 2.1

CVE-2014-5449

Zarafa WebAccess 4.1 and WebApp uses world-readable permissions for the files in their tmp directory, which allows local users to obtain sensitive information by reading temporary session data.

Vulnerability Description

Zarafa WebAccess 4.1 and WebApp uses world-readable permissions for the files in their tmp directory, which allows local users to obtain sensitive information by reading temporary session data.

CVSS Score

2.1

LOW

AV:L/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
ZarafaWebaccess4.1
ZarafaWebapp-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-5449?

CVE-2014-5449 is a vulnerability with a CVSS score of 2.1 (LOW). Zarafa WebAccess 4.1 and WebApp uses world-readable permissions for the files in their tmp directory, which allows local users to obtain sensitive information by reading temporary session data.

How severe is CVE-2014-5449?

CVE-2014-5449 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-5449?

Check the references section above for vendor advisories and patch information. Affected products include: Zarafa Webaccess, Zarafa Webapp.