SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-0704

iE Integrator 4.4.220114, when configured without a "bespoke error page" in acm.ini, allows remote attackers to obtain sensitive information via a URL that calls a non-existent .aspx script in the integrator/apps directory, which results in an error…

LOW 2.6EPSS 1.21%

Does this matter?

Lower severity and a low EPSS score (1.21%). Track it; it rarely justifies an emergency change on its own.

Description

iE Integrator 4.4.220114, when configured without a "bespoke error page" in acm.ini, allows remote attackers to obtain sensitive information via a URL that calls a non-existent .aspx script in the integrator/apps directory, which results in an error message that displays the installation path, web server name, IP, and port, session cookie information, and the IIS system username.

CVSS 2.0
2.6 LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
EPSS
1.21% probability · 67th percentile
CISA KEV
Not listed
Affected
ie/ie integrator
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.