VulnerabilityModified
CVE-1999-1236
Internet Anywhere Mail Server 2.3.1 stores passwords in plaintext in the msgboxes.dbf file, which could allow local users to gain privileges by extracting the passwords from msgboxes.dbf.
MEDIUM 4.6EPSS 0.43%
Does this matter?
Lower severity and a low EPSS score (0.43%). Track it; it rarely justifies an emergency change on its own.
Description
Internet Anywhere Mail Server 2.3.1 stores passwords in plaintext in the msgboxes.dbf file, which could allow local users to gain privileges by extracting the passwords from msgboxes.dbf.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.43% probability · 36th percentile
- CISA KEV
- Not listed
- Affected
- true north/internet anywhere mail server
- Source
- cve@mitre.org
References
- http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind9910&L=ntbugtraq&F=&S=&P=662Exploit, Vendor Advisory
- http://www.securityfocus.com/bid/731Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/3285
- http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind9910&L=ntbugtraq&F=&S=&P=662Exploit, Vendor Advisory
- http://www.securityfocus.com/bid/731Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/3285
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.