First published: Fri Mar 02 2018(Updated: )
In the JDBC driver of NetIQ Identity Manager before 4.6 sending out incorrect XML configurations could result in passwords being logged into exception logfiles.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
NetIQ Identity Manager | <4.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7434 has been assigned a medium severity level due to the potential exposure of sensitive information in exception logfiles.
To mitigate CVE-2017-7434, upgrade to NetIQ Identity Manager version 4.6 or later.
CVE-2017-7434 specifically affects the logging of passwords in exception logfiles when incorrect XML configurations are sent.
Yes, after upgrading to a version beyond 4.6, the security issue related to logging passwords is resolved.
Any organization using versions of NetIQ Identity Manager prior to 4.6 could potentially be impacted by CVE-2017-7434.