PT-2010-4699 · Novell · Novell Identity Manager

Published

2010-09-08

·

Updated

2010-09-09

·

CVE-2010-3264

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Novell Identity Manager version 3.6.1
Description The issue concerns the storage of admin tree credentials in a log file, allowing local users to obtain sensitive information. This is due to the engine installer storing these credentials in the /tmp/idmInstall.log file.
Recommendations For Novell Identity Manager version 3.6.1, consider restricting access to the /tmp/idmInstall.log file to prevent unauthorized users from reading it. Additionally, manually remove or securely delete the /tmp/idmInstall.log file after installation to minimize the risk of exposing sensitive information.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-3264

Affected Products

Novell Identity Manager