RSA enVision 4.x before 4 SP4 P3 places cleartext administrative credentials in Task Escalation e-mail messages, which allows remote attackers to obtain sensitive information by sniffing the network or leveraging access to a recipient mailbox.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Envision | Rsa | 4.0-sp1 (including) | 4.0-sp1 (including) |
Envision | Rsa | 4.0-sp2 (including) | 4.0-sp2 (including) |
Envision | Rsa | 4.0-sp3 (including) | 4.0-sp3 (including) |