CVE Vulnerabilities

CVE-2006-6438

Published: Dec 10, 2006 | Modified: Sep 10, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.9 MEDIUM
AV:L/AC:L/Au:N/C:C/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 leaves sensitive user data in http.log after an Immediate Image Overwrite (IIO), which allows local users to obtain the data by reading the http.log file.

Affected Software

Name Vendor Start Version End Version
Workcentre_255 Xerox * *
Workcentre_245 Xerox * *
Workcentre_238 Xerox * *
Workcentre_232 Xerox * *
Workcentre_232 Xerox * *
Workcentre_265 Xerox * *
Workcentre_245 Xerox * *
Workcentre_238 Xerox * *
Workcentre_275 Xerox * *
Workcentre_255 Xerox * *
Workcentre_275 Xerox * *
Workcentre_265 Xerox * *

References