CVE-2011-1424
Estado: ModificadaBaja (3.5)—
The default configuration of ExShortcut\Web.config in EMC SourceOne Email Management before 6.6 SP1, when the Mobile Services component is used, does not properly set the localOnly attribute of the trace element, which allows remote authenticated users to obtain sensitive information via ASP.NET Application Tracing.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N
- Puntuación base: 3.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.77%
- Percentil entre todas las CVEs puntuadas: 54
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-16
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2011-1424",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 3.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:S/C:P/I:N/A:N",
"authentication": "SINGLE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "security_alert@emc.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2011-05-24T23:55:02.777",
"references": [
{
"url": "http://securityreason.com/securityalert/8258",
"source": "security_alert@emc.com"
},
{
"url": "http://www.securityfocus.com/archive/1/518003/100/0/threaded",
"source": "security_alert@emc.com"
},
{
"url": "http://securityreason.com/securityalert/8258",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/518003/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-16"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The default configuration of ExShortcut\\Web.config in EMC SourceOne Email Management before 6.6 SP1, when the Mobile Services component is used, does not properly set the localOnly attribute of the trace element, which allows remote authenticated users to obtain sensitive information via ASP.NET Application Tracing."
},
{
"lang": "es",
"value": "La configuración por defecto de ExShortcut\\Web.config en EMC SourceOne Email Management anteriores a v6.6 Service Pack 1, cuando se utiliza el componente Mobile Services, no fija de forma adecuada el atributo localOnly de la traza del elemento, lo que permite a usuarios remotos autenticados a obtener información sensible a través de la aplicación ASP.NET Application Tracing."
}
],
"lastModified": "2026-06-16T23:29:19.253",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:emc:sourceone_email_management:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "04A21052-75B2-4345-962D-A50D39EBB274",
"versionEndIncluding": "6.6.0.1209"
},
{
"criteria": "cpe:2.3:a:emc:sourceone_email_management:6.5.2.3668:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BBCD8519-FCF2-45C5-9026-AAD064DAFF59"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:exchange:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "994A442C-6440-4132-A19E-3717618715BC"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:emc:sourceone_email_management:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "04A21052-75B2-4345-962D-A50D39EBB274",
"versionEndIncluding": "6.6.0.1209"
},
{
"criteria": "cpe:2.3:a:emc:sourceone_email_management:6.5.2.3668:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BBCD8519-FCF2-45C5-9026-AAD064DAFF59"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:lotus_domino:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "BE9179CA-5855-4F19-BAA6-D0A6DF468B9B"
},
{
"criteria": "cpe:2.3:a:ibm:lotus_notes:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "99CADAC9-376A-430B-B228-84F0FA401154"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "security_alert@emc.com"
}