CVE-2018-1349: NetIQ Identity Manager Driver Component Log File Information Leakage
Published Mar 26, 2018
·Updated
The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system or configuration enumeration.
Affected Software
1 affected component
NetIQ Identity Manager<=4.6
Remediation
Information
Upgrade to NetIQ Identity Manager 4.7
Event History
Mar 26, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1349?
The severity of CVE-2018-1349 is rated as medium, indicating potential information exposure that could aid attackers.
2
How do I fix CVE-2018-1349?
To fix CVE-2018-1349, upgrade to NetIQ Identity Manager version 4.7 or later.
3
What systems are affected by CVE-2018-1349?
CVE-2018-1349 affects NetIQ Identity Manager versions prior to 4.7.
4
What is the impact of CVE-2018-1349?
The impact of CVE-2018-1349 is that sensitive information in log files can be exploited for system or configuration enumeration.
5
What can I do to mitigate CVE-2018-1349 if I cannot upgrade?
If you cannot upgrade, ensure that access to the log files is restricted to trusted personnel only.