Executive Summary

Informations
Name CVE-2010-3282 First vendor Publication 2020-01-09
Vendor Cve Last vendor Modification 2020-01-29

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Overall CVSS Score 3.3
Base Score 3.3 Environmental Score 3.3
impact SubScore 1.4 Temporal Score 3.3
Exploitabality Sub Score 1.8
 
Attack Vector Local Attack Complexity Low
Privileges Required Low User Interaction None
Scope Unchanged Confidentiality Impact Low
Integrity Impact None Availability Impact None
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:M/Au:N/C:P/I:N/A:N)
Cvss Base Score 1.9 Attack Range Local
Cvss Impact Score 2.9 Attack Complexity Medium
Cvss Expoit Score 3.4 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when changing cn=config:nsslapd-rootpw, which might allow local users to obtain sensitive information by reading the log.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3282

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-312 Cleartext Storage of Sensitive Information

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:6914
 
Oval ID: oval:org.mitre.oval:def:6914
Title: HP-UX Directory Server and Red Hat Directory Server for HP-UX, Local Disclosure of Information, Privilege Escalation
Description: ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
Family: unix Class: vulnerability
Reference(s): CVE-2010-3282
Version: 11
Platform(s): HP-UX 11
Product(s):
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 21
Application 1
Application 1
Application 1

OpenVAS Exploits

Date Description
2010-10-01 Name : HP-UX Update for Directory Server and Red Hat Directory Server for HP-UX HPSB...
File : nvt/gb_hp_ux_HPSBUX02587.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
68868 Red Hat Directory Server for HP-UX Unspecified Local Privilege Escalation

68867 HP-UX Directory Server Unspecified Local Privilege Escalation

Sources (Detail)

Source Url
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=625950
https://git.fedorahosted.org/cgit/389/ds.git/commit/?id=d38ae06
https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-c02522633&do...
OVAL http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6914

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
Date Informations
2021-05-05 01:07:35
  • Multiple Updates
2021-05-04 12:12:42
  • Multiple Updates
2021-04-22 01:13:53
  • Multiple Updates
2020-05-23 01:42:37
  • Multiple Updates
2020-05-23 00:26:26
  • First insertion