Vulnerabilities > CVE-2007-3200 - Local Information Disclosure vulnerability in Novell Modular Authentication Service 3.1.2

047910
CVSS 4.9 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
NONE
Availability impact
NONE
local
low complexity
novell

Summary

NMASINST in Novell Modular Authentication Service (NMAS) 3.1.2 and earlier on NetWare logs its invoking command line to NMASINST.LOG, which might allow local users to obtain the admin username and password by reading this file.

Vulnerable Configurations

Part Description Count
Application
Novell
2