PT-2010-4699 · Novell · Novell Identity Manager
Published
2010-09-08
·
Updated
2010-09-09
·
CVE-2010-3264
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Novell Identity Manager version 3.6.1
Description
The issue concerns the storage of admin tree credentials in a log file, allowing local users to obtain sensitive information. This is due to the engine installer storing these credentials in the /tmp/idmInstall.log file.
Recommendations
For Novell Identity Manager version 3.6.1, consider restricting access to the /tmp/idmInstall.log file to prevent unauthorized users from reading it. Additionally, manually remove or securely delete the /tmp/idmInstall.log file after installation to minimize the risk of exposing sensitive information.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Novell Identity Manager