CVE-2012-2284
Summary
| CVE | CVE-2012-2284 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-10-18 17:55:00 UTC |
| Updated | 2013-04-19 03:21:00 UTC |
| Description | The (1) install and (2) upgrade processes in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 375, when Exchange Server is used, allow local users to read cleartext administrator credentials via unspecified vectors. |
Risk And Classification
Problem Types: CWE-255
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Emc | Networker Module For Microsoft Applications | 2.2.1 | All | All | All |
| Application | Emc | Networker Module For Microsoft Applications | 2.3 | All | All | All |
| Application | Emc | Networker Module For Microsoft Applications | 2.4 | All | All | All |
| Application | Emc | Networker Module For Microsoft Applications | 2.2.1 | All | All | All |
| Application | Emc | Networker Module For Microsoft Applications | 2.3 | All | All | All |
| Application | Emc | Networker Module For Microsoft Applications | 2.4 | All | All | All |
| Application | Microsoft | Exchange Server | All | All | All | All |
| Application | Microsoft | Exchange Server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| EMC NetWorker Module Remote Code Execution and Information Disclosure Vulnerabilities | BID | www.securityfocus.com | |
| 20121010 ESA-2012-025: EMC NetWorker Module for Microsoft Applications (NMM) Multiple Vulnerabilities | BUGTRAQ | archives.neohapsis.com | |
| EMC NetWorker Module for Microsoft Applications Lets Remote Users Execute Arbitrary Code and Local Users Obtain Passwords - SecurityTracker | SECTRACK | www.securitytracker.com | |
| 86157 | OSVDB | osvdb.org | |
| Security Alerts - Secunia | SECUNIA | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.