| Vulnerability Name: | CVE-2004-2414 (CCN-15600) | ||||||||
| Assigned: | 2004-03-24 | ||||||||
| Published: | 2004-03-24 | ||||||||
| Updated: | 2017-07-11 | ||||||||
| Summary: | Novell NetWare 6.5 SP 1.1, when installing or upgrading using the Overlay CDs and performing a custom installation with OpenSSH, includes sensitive password information in the (1) NIOUTPUT.TXT and (2) NI.LOG log files, which might allow local users to obtain the passwords. | ||||||||
| CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
| CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||
| References: | Source: MITRE Type: CNA CVE-2004-2414 Source: CCN Type: SA11188 Novell NetWare Admin/Install Password Disclosure Source: SECUNIA Type: Patch, Vendor Advisory 11188 Source: CCN Type: Novell Technical Information Document TID2968534 NetWare 6.5 OS SP1.1 Overlay CD Source: CONFIRM Type: Patch, Vendor Advisory http://support.novell.com/cgi-bin/search/searchtid.cgi?/2968534.htm Source: CCN Type: Novell Technical Information Document TID2968535 NetWare 6.5 Products SP1.1 Overlay CD Source: CCN Type: OSVDB ID: 4514 Novell NetWare Admin/Install Password Disclosure Source: BID Type: Patch 9934 Source: CCN Type: BID-9934 Novell NetWare Admin/Install Password Disclosure Vulnerability Source: XF Type: UNKNOWN netware-installation-file-disclosure(15600) Source: XF Type: UNKNOWN netware-installation-file-disclosure(15600) | ||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||