Release date:
Updated on:
Affected Systems:
Emc rsa Access Manager <6.2.1.03
Emc rsa Access Manager <6.2.0.11
Emc rsa Access Manager <6.1.4.22
Emc rsa Access Manager <6.1.3.39
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2014-0646
RSA Access Manager provides Secure Access Management and Access control for Web applications from a single console.
Emc rsa Access Manager 6.1.3.39, 6.1.4.22, 6.2.0.11, 6.2.1.03 and earlier versions have security vulnerabilities in the WS component during running of servers. After INFO logging is enabled, allows local users to obtain the plaintext password from the log file.
<* Source: RSA
Link: http://archives.neohapsis.com/archives/bugtraq/2014-04/att-0191/ESA-2014-029.txt
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
EMC
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.emc.com/products-solutions/index.htm
Https://knowledge.rsasecurity.com
This article permanently updates the link address: