OSVDB ID: 4151

Title: Informed Multiple Products Formerly Encrypted Information Plaintext Disclosure

Info

Disclosure

Sep 24, 2002

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Sep 24, 2002

Description

Shana Quadra (now Filenet Forms Manager) contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when encrypted files are written over previously used disk space which will disclose formerly encrypted information as plaintext at the end of the new file resulting in a loss of confidentiality.

Classification

Location: Local Access Required, Remote / Network Access
Attack Type: Cryptographic, Information Disclosure
Impact: Loss of Confidentiality, Loss of Integrity
Exploit: Exploit Rumored
Disclosure: Vendor Verified

Solution

Upgrade to version 4.0 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Filenet

Forms Manager

Unknown or Unspecified

Shana

Quadra

3.05
3.50

References

Credit

  • zel - jkounsfalsesense.com - False Sense


Direct URL: http://osvdb.org/4151