Information Exposure in Novell Identity Manager 3.6.1
CVE-2010-3264
Currently unrated
What is CVE-2010-3264?
In Novell Identity Manager version 3.6.1, the engine installer improperly stores administrative tree credentials in the /tmp/idmInstall.log file. This misconfiguration allows local users to access and read the log file, potentially exposing sensitive information related to administrative credentials, which could be exploited to gain unauthorized access to sensitive areas of the system.