2.1

CVE-2014-0103

WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitive information by reading the PHP session files.

Data is provided by the National Vulnerability Database (NVD)
ZarafaWebapp Version <= 1.5
ZarafaZarafa Version <= 7.1.9
ZarafaZarafa Version7.0
ZarafaZarafa Version7.0.1
ZarafaZarafa Version7.0.2
ZarafaZarafa Version7.0.3
ZarafaZarafa Version7.0.4
ZarafaZarafa Version7.0.5
ZarafaZarafa Version7.0.6
ZarafaZarafa Version7.0.7
ZarafaZarafa Version7.0.8
ZarafaZarafa Version7.0.9
ZarafaZarafa Version7.0.10
ZarafaZarafa Version7.0.11
ZarafaZarafa Version7.0.12
ZarafaZarafa Version7.0.13
ZarafaZarafa Version7.1.0
ZarafaZarafa Version7.1.1
ZarafaZarafa Version7.1.2
ZarafaZarafa Version7.1.3
ZarafaZarafa Version7.1.4
ZarafaZarafa Version7.1.8
FedoraprojectFedora Version19
FedoraprojectFedora Version20
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.08% 0.196
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N