389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when changing cn=config:nsslapd-rootpw, which might allow local users to obtain sensitive information by reading the log.
CVSS Details
- CVSS 3.1 Base Score: 3.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Hpux | — | Update HpuxDirSvr.GUI-HELP to the latest versionUpdate RedHatDirSvr.SLAPD-SHARED to the latest versionUpdate RedHatDirSvr.GUI-HELP to the latest versionUpdate RedHatDirSvr.ADMSVR-RUN to the latest versionUpdate RedHatDirSvr.SLAPD-RUN to the latest versionUpdate HpuxDirSvr.GUI-RUN to the latest versionUpdate RedHatDirSvr.GUI-RUN to the latest versionUpdate HpuxDirSvr.GUI-SHARED to the latest versionUpdate HpuxDirSvr.SLAPD-SHARED to the latest versionUpdate RedHatDirSvr.ADMSVR-SHARED to the latest versionUpdate HpuxDirSvr.ADMSVR-SHARED to the latest versionUpdate HpuxDirSvr.ADMSVR-RUN to the latest versionUpdate HpuxDirSvr.SLAPD-RUN to the latest versionUpdate HpuxDirSvr.CORE-RUN to the latest versionUpdate HpuxDirSvr.SLAPD-DEVEL to the latest versionUpdate RedHatDirSvr.SLAPD-DEVEL to the latest versionUpdate RedHatDirSvr.GUI-SHARED to the latest versionUpdate RedHatDirSvr.CORE-RUN to the latest version | Aug 11, 2017 | Oct 25, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub