PT-2006-5006 · Novell · Edirectory+1
Publicado
2006-08-17
·
Atualizado
2008-09-05
·
CVE-2006-4186
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Novell eDirectory version 8.7.3.8
Description
The issue concerns the iManager in eMBoxClient.jar, which writes passwords in plaintext to a log file. This allows local users to obtain passwords by reading the file.
Recommendations
For Novell eDirectory version 8.7.3.8, consider restricting access to the log file to minimize the risk of password exposure. As a temporary workaround, avoid using the iManager in eMBoxClient.jar until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Edirectory
Imanager