Shiva Access Manager World Readable LDAP Password Vulnerability
BID:1329
Info
Shiva Access Manager World Readable LDAP Password Vulnerability
| Bugtraq ID: | 1329 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 06 2000 12:00AM |
| Updated: | Jun 06 2000 12:00AM |
| Credit: | First posted to Bugtraq by Blaise St. Laurent <[email protected]> on June 6, 2000. |
| Vulnerable: |
Intel Corporation Shiva Access Manager 5.0 Solaris |
| Not Vulnerable: | |
Exploit / POC
Shiva Access Manager World Readable LDAP Password Vulnerability
cat $SHIVA_HOME_DIR/insnmgmt/shiva_access_manager/radtac.ini
(proceed then to do whatever LDAP attacks you like)
cat $SHIVA_HOME_DIR/insnmgmt/shiva_access_manager/radtac.ini
(proceed then to do whatever LDAP attacks you like)
Solution / Fix
Shiva Access Manager World Readable LDAP Password Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].