CVE-2018-1350: NetIQ Identity Manager Driver Component Information Leakage
Published Mar 26, 2018
·Updated
The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system enumeration.
Affected Software
1 affected component
NetIQ Identity Manager<=4.6
Remediation
Information
Upgrade to NetIQ Identity Manager 4.7
Event History
Mar 26, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1350?
CVE-2018-1350 has a medium severity rating due to its potential to aid in system enumeration.
2
How do I fix CVE-2018-1350?
To fix CVE-2018-1350, upgrade to NetIQ Identity Manager version 4.7 or later.
3
What versions of NetIQ Identity Manager are affected by CVE-2018-1350?
CVE-2018-1350 affects versions of NetIQ Identity Manager prior to 4.7.
4
What kind of information does CVE-2018-1350 expose?
CVE-2018-1350 exposes details in the driver log file that can be exploited for system enumeration.
5
Is there a workaround for CVE-2018-1350?
There is no specific workaround for CVE-2018-1350; the recommended action is to upgrade to a patched version.