CVE-2017-7434: NetIQ Identity Manager JDBC driver could leak passwords in exception traces
Published Mar 2, 2018
·Updated
In the JDBC driver of NetIQ Identity Manager before 4.6 sending out incorrect XML configurations could result in passwords being logged into exception logfiles.
Affected Software
1 affected component
NetIQ Identity Manager<4.6
Event History
Mar 2, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-7434?
CVE-2017-7434 has been assigned a medium severity level due to the potential exposure of sensitive information in exception logfiles.
2
How do I fix CVE-2017-7434?
To mitigate CVE-2017-7434, upgrade to NetIQ Identity Manager version 4.6 or later.
3
What types of information are affected by CVE-2017-7434?
CVE-2017-7434 specifically affects the logging of passwords in exception logfiles when incorrect XML configurations are sent.
4
Is the JDBC driver of NetIQ Identity Manager secure after the fix for CVE-2017-7434?
Yes, after upgrading to a version beyond 4.6, the security issue related to logging passwords is resolved.
5
Who is impacted by CVE-2017-7434?
Any organization using versions of NetIQ Identity Manager prior to 4.6 could potentially be impacted by CVE-2017-7434.