CVE-2025-32987 Details
Description
Arctera eDiscovery Platform before 10.3.2, when Enterprise Vault Collection Module is used, places a cleartext password on a command line in EVSearcher.
A vulnerability exists in the Arctera eDiscovery Platform versions prior to 10.3.2, specifically when the Enterprise Vault Collection Module is utilized. The issue involves the placement of a cleartext password on the command line in EVSearcher, potentially exposing sensitive information.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 15, 2025CISA-ADP
Assessed Apr 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.veritas.com/support/en_US/security/ARC25-005 | [email protected] | AdvisoryPermission RequiredVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-214 | Invocation of Process Using Visible Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Arctera eDiscovery Platform | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 15, 2025 | New CVE Received | [email protected] |
Volerion