First published: Thu Aug 17 2006(Updated: )
The iManager in eMBoxClient.jar in Novell eDirectory 8.7.3.8 writes passwords in plaintext to a log file, which allows local users to obtain passwords by reading the file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell Edirectory | =8.7.3.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4186 is considered a high severity vulnerability due to the exposure of plaintext passwords in a log file.
To fix CVE-2006-4186, update to a more secure version of Novell eDirectory that does not log passwords in plaintext.
CVE-2006-4186 affects users of Novell eDirectory version 8.7.3.8.
The consequences of CVE-2006-4186 include unauthorized access to sensitive passwords by local users.
CVE-2006-4186 is not a zero-day vulnerability as it has been publicly disclosed and known since its identification.