CVE-2018-7676: IDM Information Leakage
Published Mar 28, 2018
·Updated
The NetIQ Identity Manager, in versions prior to 4.7, userapp with log / trace enabled may leak sensitive information.
Affected Software
1 affected component
NetIQ Identity Manager<=4.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NetIQ Identity Managerto a version that resolves this vulnerability.Fixed in 4.7
Event History
Mar 28, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-7676?
CVE-2018-7676 has a medium severity rating due to its potential to expose sensitive information.
2
How do I fix CVE-2018-7676?
To fix CVE-2018-7676, upgrade to NetIQ Identity Manager version 4.7 or later.
3
What systems are affected by CVE-2018-7676?
CVE-2018-7676 affects NetIQ Identity Manager versions prior to 4.7.
4
Is CVE-2018-7676 a remote vulnerability?
CVE-2018-7676 is not classified as a remote vulnerability, but it can lead to local information exposure.
5
What type of information does CVE-2018-7676 leak?
CVE-2018-7676 may leak sensitive information through logs or traces when userapp logging is enabled.