CVE-1999-0982: High severity Sun Web-Based Enterprise Management vulnerability

Published Dec 5, 1999
·
Updated

The Sun Web-Based Enterprise Management (WBEM) installation script stores a password in plaintext in a world readable file.

Affected Software

3 affected components
Sun Web-Based Enterprise Management=2.0
Sun Web-Based Enterprise Management=1.0
Sun Solaris=8.0-beta

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Change permissions on the file created by the WBEM installation script so it is not world-readable; restrict access to the owning administrative account (for example, set owner-only permissions such as chmod 600 or apply equivalent filesystem ACLs).

    Sun Web-Based Enterprise Management (WBEM) installation script file permissions = remove world-readable
  2. Configuration

    Modify the installation script or its configuration so it does not store passwords in plaintext. Use a secure credential store or encrypt secrets at rest instead of writing cleartext passwords to files.

    Sun Web-Based Enterprise Management (WBEM) installation script password storage = do not store plaintext
  3. Compensating control

    Until the script is fixed, restrict access to the host and filesystem containing the file so only trusted administrators can read it (apply host-level ACLs, tighten filesystem permissions, and limit network/management access to trusted IPs).

  4. Operational

    Locate any plaintext password files produced by the WBEM installer, remove or sanitize those files, and rotate the affected credentials (change the passwords) for any accounts that were stored in plaintext.

Event History

Dec 5, 1999
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Jan 4, 2000
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-0982?

CVE-1999-0982 is classified as a moderate severity vulnerability due to the exposure of plaintext passwords.

2

How do I fix CVE-1999-0982?

To fix CVE-1999-0982, ensure that the installation script does not store passwords in plaintext and restrict access to sensitive files.

3

What systems are affected by CVE-1999-0982?

CVE-1999-0982 affects Sun Web-Based Enterprise Management versions 1.0 and 2.0, as well as Oracle Solaris 8.0 beta.

4

Why is CVE-1999-0982 a security risk?

CVE-1999-0982 poses a security risk because it allows unauthorized users to read sensitive passwords stored in world-readable files.

5

Is there a patch available for CVE-1999-0982?

There is no specific patch for CVE-1999-0982, but mitigating measures should be implemented to enhance file security.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203