5.3

CVE-2018-1350

NetIQ Identity Manager Driver Component Information Leakage

The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system enumeration.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netiq ≫ Identity Manager Version <= 4.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.79% 0.515
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
OpenText 2.3 0.8 1.4
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.

https://www.netiq.com/documentation/identity-manager-47/releasenotes_idm47/data/releasenotes_idm47.html
http://www.securityfocus.com/bid/103532