PT-2006-5006 · Novell · Edirectory+1
Published
2006-08-17
·
Updated
2008-09-05
·
CVE-2006-4186
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Novell eDirectory version 8.7.3.8
Description
The issue concerns the iManager in eMBoxClient.jar, which writes passwords in plaintext to a log file. This allows local users to obtain passwords by reading the file.
Recommendations
For Novell eDirectory version 8.7.3.8, consider restricting access to the log file to minimize the risk of password exposure. As a temporary workaround, avoid using the iManager in eMBoxClient.jar until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Edirectory
Imanager