CVE-2015-7238
Summary
| CVE | CVE-2015-7238 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-09-18 14:59:00 UTC |
| Updated | 2015-09-22 19:00:00 UTC |
| Description | The Secondary server in Threat Intelligence Exchange (TIE) before 1.2.0 uses weak permissions for unspecified (1) configuration files and (2) installation logs, which allows local users to obtain sensitive information by reading the files. |
Risk And Classification
Problem Types: CWE-264
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mcafee | Threat Intelligence Exchange | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| McAfee KnowledgeBase - Intel Security - Security Bulletin: Threat Intelligence Exchange 1.1.1 – Weak File Access Permissions | CONFIRM | kc.mcafee.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.