|
|
Info |
Last Modified |
| 5 months ago |
|
|
|
|
Description |
Vignette contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a login template returning response during user authentication, which will disclose account name information resulting in a loss of confidentiality.
|
|
Classification |
Location:
Local Access Required
Attack Type:
Authentication Management,
Information Disclosure
Impact:
Loss of Confidentiality
Exploit:
Exploit Unavailable
Disclosure:
OSVDB Verified
OSVDB:
Concern
|
|
Solution |
Currently, there are no known upgrades or patches to correct this issue. The vendor has posted a response for existing Vignette customers to this issue, see external reference for detail.
|
|
Products |
|
Vignette Content Suite
 |
V5 |
V6 |
V7 |
Vignette StoryServer
 |
5.0 |
4.0 |
4.1 |
|
|
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|