VWE-2016-3087 Printable Version

https://www.vaultwiki.org/pages/Book/Documentation/VWE-2016-3087
This page is a chapter in Info Known Vulnerabilities

This page has been seen 285,835 times.

    • Created by on
      Last updated by on
Common NameEavesdropper Vulnerability
VWE-IDVWE-2016-3087
Related ReportNone
SeverityMINOR
Exploit DifficultyEASY
PlatformAffects all platforms supported by the vulnerable versions.
DescriptionPermissions escalation (of view permissions). The vulnerability allows for unauthorized viewing of some user-contributed discussions. Does not affect Lite versions.
DiscoveredDecember 17, 2016
ResolvedDecember 21, 2016
Patches Available4.0.15 Patch Level 3
4.0.14 Patch Level 6
4.0.13 Patch Level 6
4.0.12 Patch Level 7
4.0.11 Patch Level 7
4.0.10 Patch Level 8
4.0.9 Patch Level 8
4.0.8 Patch Level 10
WorkaroundPhysically remove soft-deleted discussions. Update permissions so that users whose discussions would be moderated cannot start new discussions.
The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.