CVE-2010-3282

Current Description

389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when changing cn=config:nsslapd-rootpw, which might allow local users to obtain sensitive information by reading the log.

Basic Data

PublishedJanuary 09, 2020
Last ModifiedJanuary 29, 2020
Assignercve@mitre.org
Data TypeCVE
Data FormatMITRE
Data Version4.0
Problem TypeCWE-312
CVE Data Version4.0

Base Metric V2

CVSS 2 - Version2.0
CVSS 2 - Vector StringAV:L/AC:M/Au:N/C:P/I:N/A:N
CVSS 2 - Access VectorLOCAL
CVSS 2 - Access ComplexityMEDIUM
CVSS 2 - AuthenticationNONE
CVSS 2 - Confidentiality ImpactPARTIAL
CVSS 2 - Availability ImpactNONE
CVSS 2 - Base Score1.9
SeverityLOW
Exploitability Score3.4
Impact Score2.9
Obtain All Privilegefalse
Obtain User Privilegefalse
Obtain Other Privilegefalse

Base Metric V3

No data provided.

Configurations

  • OR - Configuration 1
    Cpe VersionPartVendorProductVersionUpdateEditionLanguageSW EditionTarget SWTarget HWOtherVersion Start IncludingVersion End IncludingVersion Start ExcludingVersion End Excluding
    2.3ApplicationHpHp-ux Directory Server********b.08.10.03
  • OR - Configuration 2
    Cpe VersionPartVendorProductVersionUpdateEditionLanguageSW EditionTarget SWTarget HWOtherVersion Start IncludingVersion End IncludingVersion Start ExcludingVersion End Excluding
    2.3ApplicationRedhatRedhat Directory Server*****hp-ux**b.08.00.02
  • OR - Configuration 3
    Cpe VersionPartVendorProductVersionUpdateEditionLanguageSW EditionTarget SWTarget HWOtherVersion Start IncludingVersion End IncludingVersion Start ExcludingVersion End Excluding
    2.3ApplicationFedoraproject389 Directory Server********1.2.7.1
  • OR - Configuration 4
    Cpe VersionPartVendorProductVersionUpdateEditionLanguageSW EditionTarget SWTarget HWOtherVersion Start IncludingVersion End IncludingVersion Start ExcludingVersion End Excluding
    2.3ApplicationRedhatDirectory Server8.0*******

Vulnerable Software List

VendorProductVersions
Redhat Redhat Directory Server *
Redhat Directory Server 8.0
Hp Hp-ux Directory Server *
Fedoraproject 389 Directory Server *

References

NameSourceURLTags
oval:org.mitre.oval:def:6914http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6914OVALNot Applicable
https://bugzilla.redhat.com/show_bug.cgi?id=625950https://bugzilla.redhat.com/show_bug.cgi?id=625950CONFIRMIssue Tracking Third Party Advisory
https://git.fedorahosted.org/cgit/389/ds.git/commit/?id=d38ae06https://git.fedorahosted.org/cgit/389/ds.git/commit/?id=d38ae06CONFIRMProduct
https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-c02522633&docLocale=en_UShttps://support.hpe.com/hpsc/doc/public/display?docId=emr_na-c02522633&docLocale=en_USCONFIRMVendor Advisory