CVE Vulnerabilities

CVE-2014-0103

Published: Jul 29, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitive information by reading the PHP session files.

Affected Software

NameVendorStart VersionEnd Version
WebappZarafa*1.5 (including)
ZarafaZarafa*7.1.9 (including)
ZarafaZarafa7.0 (including)7.0 (including)
ZarafaZarafa7.0.1 (including)7.0.1 (including)
ZarafaZarafa7.0.2 (including)7.0.2 (including)
ZarafaZarafa7.0.3 (including)7.0.3 (including)
ZarafaZarafa7.0.4 (including)7.0.4 (including)
ZarafaZarafa7.0.5 (including)7.0.5 (including)
ZarafaZarafa7.0.6 (including)7.0.6 (including)
ZarafaZarafa7.0.7 (including)7.0.7 (including)
ZarafaZarafa7.0.8 (including)7.0.8 (including)
ZarafaZarafa7.0.9 (including)7.0.9 (including)
ZarafaZarafa7.0.10 (including)7.0.10 (including)
ZarafaZarafa7.0.11 (including)7.0.11 (including)
ZarafaZarafa7.0.12 (including)7.0.12 (including)
ZarafaZarafa7.0.13 (including)7.0.13 (including)
ZarafaZarafa7.1.0 (including)7.1.0 (including)
ZarafaZarafa7.1.1 (including)7.1.1 (including)
ZarafaZarafa7.1.2 (including)7.1.2 (including)
ZarafaZarafa7.1.3 (including)7.1.3 (including)
ZarafaZarafa7.1.4 (including)7.1.4 (including)
ZarafaZarafa7.1.8 (including)7.1.8 (including)
FedoraFedoraproject19 (including)19 (including)
FedoraFedoraproject20 (including)20 (including)

References