PT-2010-4699 · Novell · Novell Identity Manager
Publicado
2010-09-08
·
Atualizado
2010-09-09
·
CVE-2010-3264
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Novell Identity Manager version 3.6.1
Description
The issue concerns the storage of admin tree credentials in a log file, allowing local users to obtain sensitive information. This is due to the engine installer storing these credentials in the /tmp/idmInstall.log file.
Recommendations
For Novell Identity Manager version 3.6.1, consider restricting access to the /tmp/idmInstall.log file to prevent unauthorized users from reading it. Additionally, manually remove or securely delete the /tmp/idmInstall.log file after installation to minimize the risk of exposing sensitive information.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Novell Identity Manager