Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:emc:sourceone_email_management:*:*:*:*:*:*:*:*", "matchCriteriaId": "CA4F3BDC-6F81-4238-B31D-FF74CC5226F7", "versionEndIncluding": "6.5.2.3668", "vulnerable": true}, {"criteria": "cpe:2.3:a:emc:sourceone_email_management:*:*:*:*:*:*:*:*", "matchCriteriaId": "7D553126-A393-4C8F-AA87-8F056D403576", "versionEndIncluding": "6.6.1.2108", "vulnerable": true}, {"criteria": "cpe:2.3:a:emc:sourceone_email_management:*:*:*:*:*:*:*:*", "matchCriteriaId": "086F4178-6C6E-454C-9A9F-4165627BA3F6", "versionEndIncluding": "6.7.2.0017", "vulnerable": true}, {"criteria": "cpe:2.3:a:emc:sourceone_email_management:6.5:*:*:*:*:*:*:*", "matchCriteriaId": "15148CCF-B0BA-4971-8F7E-3DD2B3263024", "vulnerable": true}, {"criteria": "cpe:2.3:a:emc:sourceone_email_management:6.6:*:*:*:*:*:*:*", "matchCriteriaId": "3AB20B79-E824-4926-A51B-D52E2EEF58B0", "vulnerable": true}, {"criteria": "cpe:2.3:a:emc:sourceone_email_management:6.6.0.1209:*:*:*:*:*:*:*", "matchCriteriaId": "7BB46E4E-AA80-4DDB-994A-3C20AF6AF94C", "vulnerable": true}, {"criteria": "cpe:2.3:a:emc:sourceone_email_management:6.7:*:*:*:*:*:*:*", "matchCriteriaId": "5DF4562E-568F-41D5-A9DD-E397150F87AB", "vulnerable": true}], "negate": false, "operator": "OR"}]}], "cveTags": [], "descriptions": [{"lang": "en", "value": "The Web Search feature in EMC SourceOne Email Management 6.5 before 6.5.2.4033, 6.6 before 6.6.1.2194, and 6.7 before 6.7.2.2033 places cleartext credentials in log files, which allows local users to obtain sensitive information by reading these files."}, {"lang": "es", "value": "La funci\u00f3n de b\u00fasqueda web de EMC SourceOne Email Management v6.5 antes de v6.5.2.4033, y6.6 antes de v6.6.1.2194, y v6.7 antes de v6.7.2.2033 coloca credenciales en texto claro en los archivos de registro (log), lo que permite a usuarios locales obtener informaci\u00f3n sensible mediante la lectura de estos archivos."}], "id": "CVE-2011-4142", "lastModified": "2025-04-11T00:51:21.963", "metrics": {"cvssMetricV2": [{"acInsufInfo": false, "baseSeverity": "LOW", "cvssData": {"accessComplexity": "LOW", "accessVector": "LOCAL", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 2.1, "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N", "version": "2.0"}, "exploitabilityScore": 3.9, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false}]}, "published": "2012-01-19T11:55:10.553", "references": [{"source": "cve@mitre.org", "url": "http://www.securityfocus.com/archive/1/521290"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.securityfocus.com/archive/1/521290"}], "sourceIdentifier": "cve@mitre.org", "vulnStatus": "Deferred", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-255"}], "source": "nvd@nist.gov", "type": "Primary"}]}