Vulnerabilities > CVE-2006-1782 - Unspecified vulnerability in SUN Solaris and Sunos

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN

Summary

Unspecified vulnerability in Solaris 8 and 9 allows local users to obtain the LDAP Directory Server root Distinguished Name (rootDN) password when a privileged user (1) runs idsconfig; or "insecurely" runs LDAP2 commands with the -w option, including (2) ldapadd, (3) ldapdelete, (4) ldapmodify, (5) ldapmodrdn, and (6) ldapsearch.

Vulnerable Configurations

Part Description Count
OS
Sun
2

Oval

accepted2006-05-31T09:45:00.000-04:00
classvulnerability
contributors
nameRobert L. Hollis
organizationThreatGuard, Inc.
descriptionUnspecified vulnerability in Solaris 8 and 9 allows local users to obtain the LDAP Directory Server root Distinguished Name (rootDN) password when a privileged user (1) runs idsconfig; or "insecurely" runs LDAP2 commands with the -w option, including (2) ldapadd, (3) ldapdelete, (4) ldapmodify, (5) ldapmodrdn, and (6) ldapsearch.
familyunix
idoval:org.mitre.oval:def:1840
statusaccepted
submitted2006-04-14T06:41:00.000-04:00
titleLDAP rootDN Password Disclosure Vulnerability
version36