Vulnerabilities > CVE-2007-4526 - Credentials Management vulnerability in multiple products
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
NONE Availability impact
NONE Summary
The Client Login Extension (CLE) in Novell Identity Manager before 3.5.1 20070730 stores the username and password in a local file, which allows local users to obtain sensitive information by reading this file.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 | |
Application | 1 |
Common Weakness Enumeration (CWE)
References
- http://osvdb.org/37320
- http://secunia.com/advisories/26555
- http://securitytracker.com/id?1018602
- http://www.securityfocus.com/bid/25420
- http://www.vupen.com/english/advisories/2007/2957
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36215
- https://secure-support.novell.com/KanisaPlatform/Publishing/177/3329402_f.SAL_Public.html