Description
389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when changing cn=config:nsslapd-rootpw, which might allow local users to obtain sensitive information by reading the log.
References (4)
Core 4
Core References
Not Applicable vdb-entry
signature
x_refsource_oval
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6914
Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=625950
Product x_refsource_confirm
https://git.fedorahosted.org/cgit/389/ds.git/commit/?id=d38ae06
Vendor Advisory x_refsource_confirm
https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-c02522633&docLocale=en_US
Scores
CVSS v3
3.3
EPSS
0.0022
EPSS Percentile
43.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Details
CWE
CWE-312
Status
published
Products (4)
fedoraproject/389_directory_server
< 1.2.7.1
hp/hp-ux_directory_server
< b.08.10.03
redhat/directory_server
8.0
redhat/redhat_directory_server
< b.08.00.02
Published
Jan 09, 2020
Tracked Since
Feb 18, 2026