CVE-2014-0103: Fedoraproject Fedora
Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.
WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitive information by reading the PHP session files.
Affected products
- Fedoraproject Fedora: version 19 only; version 20 only
- Zarafa Webapp: up to and including 1.5
- Zarafa Zarafa: up to and including 7.1.9; version 7.0 only; version 7.0.1 only; version 7.0.2 only; version 7.0.3 only; version 7.0.4 only; …
Published 2014-07-29. Last modified 2026-06-17.