CVE-2014-5447: Zarafa Webapp

Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive information by reading the PHP session files. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0103.

Affected products

  • Zarafa Webapp: version 1.6 only
  • Zarafa Zarafa: version 7.1.10 only

Published 2014-10-20. Last modified 2026-06-17.