CVE-2006-4186: Low severity Novell eDirectory vulnerability
Published Aug 17, 2006
·Updated
The iManager in eMBoxClient.jar in Novell eDirectory 8.7.3.8 writes passwords in plaintext to a log file, which allows local users to obtain passwords by reading the file.
Affected Software
1 affected component
Novell eDirectory=8.7.3.8
Remediation
Patch Available
Patch Available
Event History
Aug 17, 2006
CVE Published
12:04 AM
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4186?
CVE-2006-4186 is considered a high severity vulnerability due to the exposure of plaintext passwords in a log file.
2
How do I fix CVE-2006-4186?
To fix CVE-2006-4186, update to a more secure version of Novell eDirectory that does not log passwords in plaintext.
3
Who is affected by CVE-2006-4186?
CVE-2006-4186 affects users of Novell eDirectory version 8.7.3.8.
4
What are the consequences of CVE-2006-4186?
The consequences of CVE-2006-4186 include unauthorized access to sensitive passwords by local users.
5
Is CVE-2006-4186 a zero-day vulnerability?
CVE-2006-4186 is not a zero-day vulnerability as it has been publicly disclosed and known since its identification.