CVE-2014-5448: Zarafa

Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Zarafa 5.00 uses world-readable permissions for the files in the log directory, which allows local users to obtain sensitive information by reading the log files.

Affected products

  • Zarafa Zarafa: version 5.00 only

Published 2014-10-20. Last modified 2026-06-17.