Trend Micro InterScan eManager Bcc Disclosure Vulnerability
BID:4595
Info
Trend Micro InterScan eManager Bcc Disclosure Vulnerability
| Bugtraq ID: | 4595 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 24 2002 12:00AM |
| Updated: | Apr 24 2002 12:00AM |
| Credit: | Discovered by Ishay Sommer <[email protected]>. |
| Vulnerable: |
Trend Micro InterScan eManager 3.6 For Sun Trend Micro InterScan eManager 3.6 For Linux |
| Not Vulnerable: | |
Discussion
Trend Micro InterScan eManager Bcc Disclosure Vulnerability
Trend Micro InterScan eManager is a plug-in for InterScan which manages spam, message content, and mail delivery. It can be managed through a web-based console interface.
An issue has been reported in versions of Trend Micro InterScan eManager.
Reportedly, under certain circumstaces, eManager will disclose any email addresses included in the Bcc field to the mail recipient.
This issue is reported to happen when eManager identifies the message being sent is Spam.
It should be noted that this issue was reported in 3.6, other versions may also be subject to this issue.
Trend Micro InterScan eManager is a plug-in for InterScan which manages spam, message content, and mail delivery. It can be managed through a web-based console interface.
An issue has been reported in versions of Trend Micro InterScan eManager.
Reportedly, under certain circumstaces, eManager will disclose any email addresses included in the Bcc field to the mail recipient.
This issue is reported to happen when eManager identifies the message being sent is Spam.
It should be noted that this issue was reported in 3.6, other versions may also be subject to this issue.
Exploit / POC
Trend Micro InterScan eManager Bcc Disclosure Vulnerability
No exploit code required.
No exploit code required.
Solution / Fix
Trend Micro InterScan eManager Bcc Disclosure Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.