First published: Tue Jun 06 2000(Updated: )
When configured to store configuration information in an LDAP directory, Shiva Access Manager 5.0.0 stores the root DN (Distinguished Name) name and password in cleartext in a file that is world readable, which allows local users to compromise the LDAP server.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Shiva Access Manager | =5.0 | |
=5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0516 is considered a high severity vulnerability due to the potential compromise of LDAP server credentials.
To fix CVE-2000-0516, restrict file permissions on the configuration file to prevent unauthorized access.
CVE-2000-0516 affects Intel Shiva Access Manager version 5.0 on Solaris.
CVE-2000-0516 compromises the root DN and password stored in cleartext, allowing local users unauthorized access.
CVE-2000-0516 is primarily a local vulnerability, as it requires local access to the vulnerable system to exploit.