CVE-2011-0993: Low severity Novell Suse Lifecycle Management Server vulnerability
Published Apr 16, 2014
·Updated
SUSE Lifecycle Management Server before 1.1 uses world readable postgres credentials, which allows local users to obtain sensitive information via unspecified vectors.
Affected Software
1 affected component
Novell Suse Lifecycle Management Server<=1.0
Event History
Apr 16, 2014
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:37 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2011-0993?
CVE-2011-0993 is classified as a high severity vulnerability due to exposure of sensitive information.
2
How do I fix CVE-2011-0993?
To fix CVE-2011-0993, ensure that the postgres credentials are no longer readable by unauthorized users.
3
Who is affected by CVE-2011-0993?
CVE-2011-0993 affects all versions of SUSE Lifecycle Management Server prior to 1.1.
4
What type of vulnerability is CVE-2011-0993?
CVE-2011-0993 is an information disclosure vulnerability related to improper permissions on database credentials.
5
Can local users exploit CVE-2011-0993?
Yes, local users can exploit CVE-2011-0993 to gain access to sensitive postgres credentials.