CVE-2014-5449: Zarafa Webaccess

Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Zarafa WebAccess 4.1 and WebApp uses world-readable permissions for the files in their tmp directory, which allows local users to obtain sensitive information by reading temporary session data.

Affected products

  • Zarafa Webaccess: version 4.1 only
  • Zarafa Webapp: affected versions not specified

Published 2014-10-20. Last modified 2026-06-17.