{"api_version":"1","generated_at":"2026-07-24T18:23:23+00:00","cve":"CVE-2007-3700","urls":{"html":"https://cve.report/CVE-2007-3700","api":"https://cve.report/api/cve/CVE-2007-3700.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-3700","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-3700"},"summary":{"title":"CVE-2007-3700","description":"Sun Java System Access Manager (formerly Java System Identity Server) before 20070710, when the message debug level is configured in the com.iplanet.services.debug.level property in AMConfig.properties, logs cleartext login passwords, which allows local users to gain privileges by reading /var/opt/SUNWam/debug/amAuth.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-07-11 23:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"1.7","severity":"","vector":"AV:L/AC:L/Au:S/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:S/C:P/I:N/A:N","baseScore":1.7,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2007/2496","name":"http://www.vupen.com/english/advisories/2007/2496","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-200386-1","name":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-200386-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://www.securitytracker.com/id?1018370","name":"http://www.securitytracker.com/id?1018370","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Sun Java System Access Manager Discloses Passwords to Local Users - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35339","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35339","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/26030","name":"http://secunia.com/advisories/26030","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Sun Java System Access Manager \"message\" Debug Level Password Disclosure - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-101918-1","name":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-101918-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://www.securityfocus.com/bid/24859","name":"http://www.securityfocus.com/bid/24859","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Sun Java System Access Manager Logging Output Password Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://osvdb.org/37249","name":"http://osvdb.org/37249","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-3700","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-3700","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"3700","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sun","cpe5":"java_system_access_manager","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T14:28:51.294Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"24859","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/24859"},{"name":"ADV-2007-2496","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/2496"},{"name":"26030","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26030"},{"name":"37249","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/37249"},{"name":"1018370","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1018370"},{"name":"101918","tags":["vendor-advisory","x_refsource_SUNALERT","x_transferred"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-101918-1"},{"name":"200386","tags":["vendor-advisory","x_refsource_SUNALERT","x_transferred"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-200386-1"},{"name":"sun-jsam-message-information-disclosure(35339)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35339"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-07-10T00:00:00.000Z","descriptions":[{"lang":"en","value":"Sun Java System Access Manager (formerly Java System Identity Server) before 20070710, when the message debug level is configured in the com.iplanet.services.debug.level property in AMConfig.properties, logs cleartext login passwords, which allows local users to gain privileges by reading /var/opt/SUNWam/debug/amAuth."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"24859","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/24859"},{"name":"ADV-2007-2496","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/2496"},{"name":"26030","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26030"},{"name":"37249","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/37249"},{"name":"1018370","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1018370"},{"name":"101918","tags":["vendor-advisory","x_refsource_SUNALERT"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-101918-1"},{"name":"200386","tags":["vendor-advisory","x_refsource_SUNALERT"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-200386-1"},{"name":"sun-jsam-message-information-disclosure(35339)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35339"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-3700","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Sun Java System Access Manager (formerly Java System Identity Server) before 20070710, when the message debug level is configured in the com.iplanet.services.debug.level property in AMConfig.properties, logs cleartext login passwords, which allows local users to gain privileges by reading /var/opt/SUNWam/debug/amAuth."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"24859","refsource":"BID","url":"http://www.securityfocus.com/bid/24859"},{"name":"ADV-2007-2496","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/2496"},{"name":"26030","refsource":"SECUNIA","url":"http://secunia.com/advisories/26030"},{"name":"37249","refsource":"OSVDB","url":"http://osvdb.org/37249"},{"name":"1018370","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1018370"},{"name":"101918","refsource":"SUNALERT","url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-101918-1"},{"name":"200386","refsource":"SUNALERT","url":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-200386-1"},{"name":"sun-jsam-message-information-disclosure(35339)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35339"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-3700","datePublished":"2007-07-11T23:00:00.000Z","dateReserved":"2007-07-11T00:00:00.000Z","dateUpdated":"2024-08-07T14:28:51.294Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-07-11 23:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:S/C:P/I:N/A:N","baseScore":1.7,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.1,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sun:java_system_access_manager:*:*:*:*:*:*:*:*","matchCriteriaId":"B2402481-C481-4FB6-9415-2504B3B93F7E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"3700","Ordinal":"1","Title":"CVE-2007-3700","CVE":"CVE-2007-3700","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"3700","Ordinal":"1","NoteData":"Sun Java System Access Manager (formerly Java System Identity Server) before 20070710, when the message debug level is configured in the com.iplanet.services.debug.level property in AMConfig.properties, logs cleartext login passwords, which allows local users to gain privileges by reading /var/opt/SUNWam/debug/amAuth.","Type":"Description","Title":"CVE-2007-3700"},{"CveYear":"2007","CveId":"3700","Ordinal":"2","NoteData":"2007-07-11","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"3700","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}