PT-2006-5006 · Novell · Edirectory+1

Published

2006-08-17

·

Updated

2008-09-05

·

CVE-2006-4186

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Novell eDirectory version 8.7.3.8
Description The issue concerns the iManager in eMBoxClient.jar, which writes passwords in plaintext to a log file. This allows local users to obtain passwords by reading the file.
Recommendations For Novell eDirectory version 8.7.3.8, consider restricting access to the log file to minimize the risk of password exposure. As a temporary workaround, avoid using the iManager in eMBoxClient.jar until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-4186

Affected Products

Edirectory
Imanager