Описание
389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when changing cn=config:nsslapd-rootpw, which might allow local users to obtain sensitive information by reading the log.
Ссылки
- Not Applicable
- Issue TrackingThird Party Advisory
- Product
- Vendor Advisory
- Not Applicable
- Issue TrackingThird Party Advisory
- Product
- Vendor Advisory
Уязвимые конфигурации
EPSS
3.3 Low
CVSS3
1.9 Low
CVSS2
Дефекты
Связанные уязвимости
389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when changing cn=config:nsslapd-rootpw, which might allow local users to obtain sensitive information by reading the log.
389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when changing cn=config:nsslapd-rootpw, which might allow local users to obtain sensitive information by reading the log.
EPSS
3.3 Low
CVSS3
1.9 Low
CVSS2