CVE-2007-3700: Low severity Sun Java System Access Manager vulnerability
Sun Java System Access Manager (formerly Java System Identity Server) before 20070710, when the message debug level is configured in the com.iplanet.services.debug.level property in AMConfig.properties, logs cleartext login passwords, which allows local users to gain privileges by reading /var/opt/SUNWam/debug/amAuth.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3700?
CVE-2007-3700 is classified as a vulnerability that allows local users to access sensitive information.
How do I fix CVE-2007-3700?
To fix CVE-2007-3700, upgrade to Sun Java System Access Manager version 20070710 or later.
What specific information does CVE-2007-3700 expose?
CVE-2007-3700 exposes cleartext login passwords in the logs when the debug level is configured improperly.
Who can exploit the CVE-2007-3700 vulnerability?
Local users with access to the logging files can exploit the CVE-2007-3700 vulnerability.
What systems are affected by CVE-2007-3700?
CVE-2007-3700 affects Sun Java System Access Manager versions prior to 20070710.