Vulnerabilities > CVE-2006-1782 - Unspecified vulnerability in SUN Solaris and Sunos

047910
CVSS 2.1 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
local
low complexity
sun

Summary

Unspecified vulnerability in Solaris 8 and 9 allows local users to obtain the LDAP Directory Server root Distinguished Name (rootDN) password when a privileged user (1) runs idsconfig; or "insecurely" runs LDAP2 commands with the -w option, including (2) ldapadd, (3) ldapdelete, (4) ldapmodify, (5) ldapmodrdn, and (6) ldapsearch.

Vulnerable Configurations

Part Description Count
OS
Sun
2

Oval

accepted2006-05-31T09:45:00.000-04:00
classvulnerability
contributors
nameRobert L. Hollis
organizationThreatGuard, Inc.
descriptionUnspecified vulnerability in Solaris 8 and 9 allows local users to obtain the LDAP Directory Server root Distinguished Name (rootDN) password when a privileged user (1) runs idsconfig; or "insecurely" runs LDAP2 commands with the -w option, including (2) ldapadd, (3) ldapdelete, (4) ldapmodify, (5) ldapmodrdn, and (6) ldapsearch.
familyunix
idoval:org.mitre.oval:def:1840
statusaccepted
submitted2006-04-14T06:41:00.000-04:00
titleLDAP rootDN Password Disclosure Vulnerability
version36