First published: Sat Aug 25 2007(Updated: )
The Client Login Extension (CLE) in Novell Identity Manager before 3.5.1 20070730 stores the username and password in a local file, which allows local users to obtain sensitive information by reading this file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Micro Focus Identity Manager | <=3.5 | |
Novell Client Login Extension |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4526 is considered a high severity vulnerability due to the potential exposure of sensitive information.
To fix CVE-2007-4526, upgrade to Novell Identity Manager version 3.5.1 or later.
Failure to address CVE-2007-4526 could lead to unauthorized access to usernames and passwords stored in local files.
Users of Novell Identity Manager versions before 3.5.1 are affected by CVE-2007-4526.
The vulnerability specifically affects the Client Login Extension (CLE) in Novell Identity Manager.