WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitive information by reading the PHP session files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Webapp | Zarafa | * | 1.5 (including) |
Zarafa | Zarafa | * | 7.1.9 (including) |
Zarafa | Zarafa | 7.0 (including) | 7.0 (including) |
Zarafa | Zarafa | 7.0.1 (including) | 7.0.1 (including) |
Zarafa | Zarafa | 7.0.2 (including) | 7.0.2 (including) |
Zarafa | Zarafa | 7.0.3 (including) | 7.0.3 (including) |
Zarafa | Zarafa | 7.0.4 (including) | 7.0.4 (including) |
Zarafa | Zarafa | 7.0.5 (including) | 7.0.5 (including) |
Zarafa | Zarafa | 7.0.6 (including) | 7.0.6 (including) |
Zarafa | Zarafa | 7.0.7 (including) | 7.0.7 (including) |
Zarafa | Zarafa | 7.0.8 (including) | 7.0.8 (including) |
Zarafa | Zarafa | 7.0.9 (including) | 7.0.9 (including) |
Zarafa | Zarafa | 7.0.10 (including) | 7.0.10 (including) |
Zarafa | Zarafa | 7.0.11 (including) | 7.0.11 (including) |
Zarafa | Zarafa | 7.0.12 (including) | 7.0.12 (including) |
Zarafa | Zarafa | 7.0.13 (including) | 7.0.13 (including) |
Zarafa | Zarafa | 7.1.0 (including) | 7.1.0 (including) |
Zarafa | Zarafa | 7.1.1 (including) | 7.1.1 (including) |
Zarafa | Zarafa | 7.1.2 (including) | 7.1.2 (including) |
Zarafa | Zarafa | 7.1.3 (including) | 7.1.3 (including) |
Zarafa | Zarafa | 7.1.4 (including) | 7.1.4 (including) |
Zarafa | Zarafa | 7.1.8 (including) | 7.1.8 (including) |
Fedora | Fedoraproject | 19 (including) | 19 (including) |
Fedora | Fedoraproject | 20 (including) | 20 (including) |