First published: Mon Mar 26 2018(Updated: )
The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system or configuration enumeration.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Micro Focus Identity Manager | <=4.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-1349 is rated as medium, indicating potential information exposure that could aid attackers.
To fix CVE-2018-1349, upgrade to NetIQ Identity Manager version 4.7 or later.
CVE-2018-1349 affects NetIQ Identity Manager versions prior to 4.7.
The impact of CVE-2018-1349 is that sensitive information in log files can be exploited for system or configuration enumeration.
If you cannot upgrade, ensure that access to the log files is restricted to trusted personnel only.