LOW · 1.7

CVE-2007-3700

Sun Java System Access Manager (formerly Java System Identity Server) before 20070710, when the message debug level is configured in the com.iplanet.services.debug.level property in AMConfig.propertie...

Vulnerability Description

Sun Java System Access Manager (formerly Java System Identity Server) before 20070710, when the message debug level is configured in the com.iplanet.services.debug.level property in AMConfig.properties, logs cleartext login passwords, which allows local users to gain privileges by reading /var/opt/SUNWam/debug/amAuth.

CVSS Score

1.7

LOW

AV:L/AC:L/Au:S/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
SunJava System Access ManagerAll versions

References

FAQ

What is CVE-2007-3700?

CVE-2007-3700 is a vulnerability with a CVSS score of 1.7 (LOW). Sun Java System Access Manager (formerly Java System Identity Server) before 20070710, when the message debug level is configured in the com.iplanet.services.debug.level property in AMConfig.propertie...

How severe is CVE-2007-3700?

CVE-2007-3700 has been rated LOW with a CVSS base score of 1.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-3700?

Check the references section above for vendor advisories and patch information. Affected products include: Sun Java System Access Manager.