Epicor Enterprise CVE-2014-4311 Password Disclosure Vulnerability
BID:70189
Info
Epicor Enterprise CVE-2014-4311 Password Disclosure Vulnerability
| Bugtraq ID: | 70189 |
| Class: | Design Error |
| CVE: |
CVE-2014-4311 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 30 2014 12:00AM |
| Updated: | Sep 30 2014 12:00AM |
| Credit: | Fara Rustein fararustein |
| Vulnerable: |
Epicor Enterprise 7.4 |
| Not Vulnerable: | |
Discussion
Epicor Enterprise CVE-2014-4311 Password Disclosure Vulnerability
Epicor Enterprise is prone to a password-disclosure vulnerability.
An attacker can exploit this issue to disclose sensitive information. Information obtained may lead to further attacks.
Epicor Enterprise 7.4 is vulnerable; other versions may also be affected.
Epicor Enterprise is prone to a password-disclosure vulnerability.
An attacker can exploit this issue to disclose sensitive information. Information obtained may lead to further attacks.
Epicor Enterprise 7.4 is vulnerable; other versions may also be affected.
Exploit / POC
Epicor Enterprise CVE-2014-4311 Password Disclosure Vulnerability
An attacker can exploit this issue using a browser.
An attacker can exploit this issue using a browser.
Solution / Fix
Epicor Enterprise CVE-2014-4311 Password Disclosure Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
Epicor Enterprise CVE-2014-4311 Password Disclosure Vulnerability
References:
References:
- Epicor Enterprise Homepage (Epicor)
- Epicor Enterprise vulnerabilities (Seclist.org)