Vulnerability CVE-2010-3282


Published: 2020-01-09   Modified: 2020-01-10

Description:
389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when changing cn=config:nsslapd-rootpw, which might allow local users to obtain sensitive information by reading the log.

Type:

CWE-312

(Cleartext Storage of Sensitive Information)

CVSS2 => (AV:L/AC:M/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
1.9/10
2.9/10
3.4/10
Exploit range
Attack complexity
Authentication
Local
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Redhat -> Redhat directory server 
Redhat -> Directory server 
HP -> Hp-ux directory server 
Fedoraproject -> 389 directory server 

 References:
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6914
https://bugzilla.redhat.com/show_bug.cgi?id=625950
https://git.fedorahosted.org/cgit/389/ds.git/commit/?id=d38ae06
https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-c02522633&docLocale=en_US

Copyright 2023, cxsecurity.com

 

Back to Top