CVE-2010-3264: Low severity Novell Identity Manager vulnerability
Published Sep 8, 2010
·Updated
The engine installer in Novell Identity Manager (aka IDM) 3.6.1 stores admin tree credentials in /tmp/idmInstall.log, which allows local users to obtain sensitive information by reading this file.
Affected Software
1 affected component
Novell Identity Manager=3.6.1
Event History
Sep 8, 2010
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-3264?
CVE-2010-3264 is considered a medium severity vulnerability due to the exposure of sensitive admin credentials.
2
How do I fix CVE-2010-3264?
To fix CVE-2010-3264, ensure that sensitive logs are secured and restrict access to the /tmp/idmInstall.log file.
3
Who is affected by CVE-2010-3264?
Users of Novell Identity Manager version 3.6.1 are affected by CVE-2010-3264.
4
What information is exposed through CVE-2010-3264?
CVE-2010-3264 exposes sensitive admin tree credentials stored in a log file.
5
Can local users exploit CVE-2010-3264?
Yes, local users can exploit CVE-2010-3264 by accessing the unsecured log file to obtain sensitive information.