RSA enVision Environmental Variable Information Disclosure Vulnerability
BID:51682
Info
RSA enVision Environmental Variable Information Disclosure Vulnerability
| Bugtraq ID: | 51682 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-4143 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 26 2012 12:00AM |
| Updated: | Jan 26 2012 12:00AM |
| Credit: | Reported by the vendor |
| Vulnerable: |
RSA Security enVision Platform 3.7 SP1 RSA Security enVision Platform 3.7 RSA Security enVision Platform 3.5.2 RSA Security enVision Platform 3.5.1 RSA Security enVision Platform 3.5 RSA Security enVision Platform 4.0 RSA Security enVision Platform 3.7 SP 1 |
| Not Vulnerable: |
RSA Security enVision Platform 4.1 P3 RSA Security enVision Platform 4.0 SP4 P5 |
Discussion
RSA enVision Environmental Variable Information Disclosure Vulnerability
RSA enVision is prone to an information-disclosure vulnerability because it fails to properly sanitize user-supplied input.
Attackers can exploit these issues to gain access to sensitive information. Information obtained may aid in further attacks.
RSA enVision versions 4.x are vulnerable.
RSA enVision is prone to an information-disclosure vulnerability because it fails to properly sanitize user-supplied input.
Attackers can exploit these issues to gain access to sensitive information. Information obtained may aid in further attacks.
RSA enVision versions 4.x are vulnerable.
Exploit / POC
RSA enVision Environmental Variable Information Disclosure Vulnerability
Attackers can use readily available tools to exploit these issues.
Attackers can use readily available tools to exploit these issues.
Solution / Fix
RSA enVision Environmental Variable Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
RSA enVision Environmental Variable Information Disclosure Vulnerability
References:
References:
- enVision Homepage (RSA)