Novell Identity Manager Client Login Extension Local Information Disclosure Vulnerability
BID:25420
Info
Novell Identity Manager Client Login Extension Local Information Disclosure Vulnerability
| Bugtraq ID: | 25420 |
| Class: | Design Error |
| CVE: |
CVE-2007-4526 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 23 2007 12:00AM |
| Updated: | May 07 2015 05:35PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Novell Identity Manager 3.5.1 Novell Identity Manager 3.5 |
| Not Vulnerable: |
Novell Identity Manager 3.5.1 20070730 |
Discussion
Novell Identity Manager Client Login Extension Local Information Disclosure Vulnerability
Novell Identity Manager is prone to a local information-disclosure vulnerability that arises because of a design error.
An attacker could exploit this issue to gain access to usernames and passwords for the application. Information obtained may aid in further attacks.
Versions prior to Novell Identity Manager 3.5.1 20070730 are vulnerable.
Novell Identity Manager is prone to a local information-disclosure vulnerability that arises because of a design error.
An attacker could exploit this issue to gain access to usernames and passwords for the application. Information obtained may aid in further attacks.
Versions prior to Novell Identity Manager 3.5.1 20070730 are vulnerable.
Exploit / POC
Novell Identity Manager Client Login Extension Local Information Disclosure Vulnerability
An attacker can exploit this issue by gaining local interactive access to the affected computer.
An attacker can exploit this issue by gaining local interactive access to the affected computer.
Solution / Fix
Novell Identity Manager Client Login Extension Local Information Disclosure Vulnerability
Solution:
Novell has released an update and an advisory to address this issue. Please see the references for more information.
Novell Identity Manager 3.5
Novell Identity Manager 3.5.1
Solution:
Novell has released an update and an advisory to address this issue. Please see the references for more information.
Novell Identity Manager 3.5
-
Novell idmcle.exe
http://download.novell.com/Download?buildid=APPtPqDcaVU~
Novell Identity Manager 3.5.1
-
Novell idmcle.exe
http://download.novell.com/Download?buildid=APPtPqDcaVU~
References
Novell Identity Manager Client Login Extension Local Information Disclosure Vulnerability
References:
References: