Release date:
Updated on:
Affected Systems:
RSA Security enVision Platform 4.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 49317
Cve id: CVE-2011-2736, CVE-2011-2737
RSA EnVision is a platform for collecting and analyzing Security events and logs in the RSA Security product family.
RSA EnVision has multiple information leakage vulnerabilities. Remote attackers can exploit these vulnerabilities to leak administrator creden。 or retrieve arbitrary files.
1) unknown details of Test Escalation emails can be exploited to leak plain text creden.
2) unknown details can be exploited to leak Arbitrary File Content.
<* Source: vendor
Link: http://archives.neohapsis.com/archives/bugtraq/2011-08/att-0149/ESA-2011-030.txt
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
RSA Security
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.rsasecurity.com