CVE-2013-3273

EMC RSA Authentication Manager 8.0 before P2 and 7.1 before SP4 P26, as used in Appliance 3.0, does not omit the cleartext administrative password from trace logging in custom SDK applications, which allows local users to obtain sensitive information by reading the trace log file.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:emc:rsa_authentication_manager:7.1:*:*:*:*:*:*:*
cpe:2.3:a:emc:rsa_authentication_manager:7.1:sp2:*:*:*:*:*:*
cpe:2.3:a:emc:rsa_authentication_manager:7.1:sp3:*:*:*:*:*:*
cpe:2.3:a:emc:rsa_authentication_manager:8.0:p1:*:*:*:*:*:*
cpe:2.3:a:rsa:authentication_manager:7.1:sp1:*:*:*:*:*:*
cpe:2.3:a:rsa:authentication_manager:8.0:*:*:*:*:*:*:*

History

21 Nov 2024, 01:53

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/bugtraq/2013-07/0046.html - () http://archives.neohapsis.com/archives/bugtraq/2013-07/0046.html -

Information

Published : 2013-07-08 20:55

Updated : 2024-11-21 01:53


NVD link : CVE-2013-3273

Mitre link : CVE-2013-3273

CVE.ORG link : CVE-2013-3273


JSON object : View

Products Affected

rsa

  • authentication_manager

emc

  • rsa_authentication_manager
CWE
CWE-255

Credentials Management Errors