The Client Login Extension (CLE) in Novell Identity Manager before 3.5.1 20070730 stores the username and password in a local file, which allows local users to obtain sensitive information by reading this file.
References
Link | Resource |
---|---|
https://secure-support.novell.com/KanisaPlatform/Publishing/177/3329402_f.SAL_Public.html | Patch |
http://secunia.com/advisories/26555 | Patch Vendor Advisory |
http://securitytracker.com/id?1018602 | Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/25420 | Third Party Advisory VDB Entry |
http://osvdb.org/37320 | Broken Link |
http://www.vupen.com/english/advisories/2007/2957 | Third Party Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/36215 | VDB Entry |
Configurations
Configuration 1 (hide)
|
Information
Published : 2007-08-24 17:17
Updated : 2018-09-27 14:30
NVD link : CVE-2007-4526
Mitre link : CVE-2007-4526
JSON object : View
CWE
CWE-255
Credentials Management Errors
Products Affected
netiq
- identity_manager
novell
- client_login_extension_\(cle\)