Vulnerability Description
389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when changing cn=config:nsslapd-rootpw, which might allow local users to obtain sensitive information by reading the log.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hp | Hp-Ux Directory Server | < b.08.10.03 |
| Redhat | Redhat Directory Server | < b.08.00.02 |
| Fedoraproject | 389 Directory Server | < 1.2.7.1 |
| Redhat | Directory Server | 8.0 |
Related Weaknesses (CWE)
References
- http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6914Not Applicable
- https://bugzilla.redhat.com/show_bug.cgi?id=625950Issue TrackingThird Party Advisory
- https://git.fedorahosted.org/cgit/389/ds.git/commit/?id=d38ae06Product
- https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-c02522633&docLocaleVendor Advisory
- http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6914Not Applicable
- https://bugzilla.redhat.com/show_bug.cgi?id=625950Issue TrackingThird Party Advisory
- https://git.fedorahosted.org/cgit/389/ds.git/commit/?id=d38ae06Product
- https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-c02522633&docLocaleVendor Advisory
FAQ
What is CVE-2010-3282?
CVE-2010-3282 is a vulnerability with a CVSS score of 3.3 (LOW). 389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw)...
How severe is CVE-2010-3282?
CVE-2010-3282 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-3282?
Check the references section above for vendor advisories and patch information. Affected products include: Hp Hp-Ux Directory Server, Redhat Redhat Directory Server, Fedoraproject 389 Directory Server, Redhat Directory Server.