First published: Fri Mar 02 2018(Updated: )
The NetIQ Identity Manager Oracle EBS driver before 4.0.2.0 sent EBS logs containing the driver authentication password, potentially disclosing this to attackers able to read the EBS tables.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
NetIQ Identity Manager | <4.0.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9278 is considered a high severity vulnerability due to its potential to expose authentication credentials.
To fix CVE-2017-9278, upgrade to NetIQ Identity Manager version 4.0.2.0 or later.
CVE-2017-9278 affects the NetIQ Identity Manager Oracle EBS driver versions prior to 4.0.2.0.
CVE-2017-9278 potentially exposes the driver authentication password through EBS logs.
Attackers with access to read the Oracle EBS tables are at risk of exploiting CVE-2017-9278.