| Vulnerability Name: | CVE-2006-2185 (CCN-26488) | ||||||||
| Assigned: | 2006-05-08 | ||||||||
| Published: | 2006-05-08 | ||||||||
| Updated: | 2017-07-20 | ||||||||
| Summary: | PORTAL.NLM in Novell Netware 6.5 SP5 writes the username and password in cleartext to the abend.log log file when the groupOperationsMethod function fails, which allows context-dependent attackers to gain privileges. | ||||||||
| CVSS v3 Severity: | 2.8 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N)
| ||||||||
| CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||
| References: | Source: MITRE Type: CNA CVE-2006-2185 Source: CCN Type: SA20288 Novell Netware abend.log User Credentials Disclosure Source: SECUNIA Type: UNKNOWN 20288 Source: CCN Type: SECTRACK ID: 1016106 NetWare `PORTAL.NLM` Crash May Cause the Target User`s Password to Be Written to the Log File Source: SECTRACK Type: Patch 1016106 Source: CCN Type: Novell Technical Information Document TID2973698 HTTP Stack Update for NetWare 6.5 SP5 Source: CONFIRM Type: Patch http://support.novell.com/cgi-bin/search/searchtid.cgi?2973698.htm Source: OSVDB Type: UNKNOWN 25780 Source: CCN Type: OSVDB ID: 25780 Novell NetWare abend.log User Credentials Disclosure Source: BID Type: UNKNOWN 18017 Source: CCN Type: BID-18017 Novell NetWare Local Information Disclosure Vulnerability Source: VUPEN Type: UNKNOWN ADV-2006-1829 Source: XF Type: UNKNOWN netware-portal-information-disclosure(26488) Source: XF Type: UNKNOWN netware-portal-information-disclosure(26488) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||