First published: Wed Sep 08 2010(Updated: )
The engine installer in Novell Identity Manager (aka IDM) 3.6.1 stores admin tree credentials in /tmp/idmInstall.log, which allows local users to obtain sensitive information by reading this file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Micro Focus Identity Manager | =3.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3264 is considered a medium severity vulnerability due to the exposure of sensitive admin credentials.
To fix CVE-2010-3264, ensure that sensitive logs are secured and restrict access to the /tmp/idmInstall.log file.
Users of Novell Identity Manager version 3.6.1 are affected by CVE-2010-3264.
CVE-2010-3264 exposes sensitive admin tree credentials stored in a log file.
Yes, local users can exploit CVE-2010-3264 by accessing the unsecured log file to obtain sensitive information.