HP-UX Directory Server Password Disclosure Vulnerabilities
Last Update Date:
29 May 2013 11:52
Release Date:
29 May 2013
3991
Views
RISK: Medium Risk
TYPE: Servers - Network Management
Multiple vulnerabilities have been identified in HP-UX Directory Server, which can be exploited by remote authenticated user or local user to view passwords.
- A local user can access the plaintext password in certain cases.
- A remote authenticated user can view the password for a target LDAP user when audit logging is enabled by reading the audit log.
Impact
- Information Disclosure
System / Technologies affected
- HP-UX Directory Server B.08.10.04
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Upgrade to HP-UX Directory Server B.08.10.05
https://h20392.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=HPDirSvr
Vulnerability Identifier
Source
Related Link
Share with