Zarafa Webapp vulnerabilities
3 known vulnerabilities affecting zarafa/webapp.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM1LOW2
Vulnerabilities
Page 1 of 1
CVE-2014-9465P4MEDIUMCVSS 5.0≤ 2.02015-02-19
CVE-2014-9465 [MEDIUM] CWE-399 CVE-2014-9465: senddocument.php in Zarafa WebApp before 2.0 beta 3 and WebAccess in Zarafa Collaboration Platform (
senddocument.php in Zarafa WebApp before 2.0 beta 3 and WebAccess in Zarafa Collaboration Platform (ZCP) 7.x before 7.1.12 beta 1 and 7.2.x before 7.2.0 beta 1 allows remote attackers to cause a denial of service (/tmp disk consumption) by uploading a large number of files.
nvd
CVE-2014-0103P4LOWCVSS 2.1≤ 1.52014-07-29
CVE-2014-0103 [LOW] CWE-310 CVE-2014-0103: WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allow
WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitive information by reading the PHP session files.
nvd
CVE-2014-5447P4LOWCVSS 2.1v1.62014-10-20
CVE-2014-5447 [LOW] CVE-2014-5447: Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows
Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive information by reading the PHP session files. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0103.
nvd