First published: Wed Jul 11 2007(Updated: )
Sun Java System Access Manager (formerly Java System Identity Server) before 20070710, when the message debug level is configured in the com.iplanet.services.debug.level property in AMConfig.properties, logs cleartext login passwords, which allows local users to gain privileges by reading /var/opt/SUNWam/debug/amAuth.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Access Manager |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3700 is classified as a vulnerability that allows local users to access sensitive information.
To fix CVE-2007-3700, upgrade to Sun Java System Access Manager version 20070710 or later.
CVE-2007-3700 exposes cleartext login passwords in the logs when the debug level is configured improperly.
Local users with access to the logging files can exploit the CVE-2007-3700 vulnerability.
CVE-2007-3700 affects Sun Java System Access Manager versions prior to 20070710.