Vulnerability Details CVE-2010-3282
389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when changing cn=config:nsslapd-rootpw, which might allow local users to obtain sensitive information by reading the log.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 14.1%
CVSS Severity
CVSS v3 Score 3.3
CVSS v2 Score 1.9
Products affected by CVE-2010-3282
-
cpe:2.3:a:fedoraproject:389_directory_server:-
-
cpe:2.3:a:fedoraproject:389_directory_server:1.1.46
-
cpe:2.3:a:fedoraproject:389_directory_server:1.2.1
-
cpe:2.3:a:fedoraproject:389_directory_server:1.2.2
-
cpe:2.3:a:fedoraproject:389_directory_server:1.2.3
-
cpe:2.3:a:fedoraproject:389_directory_server:1.2.5
-
cpe:2.3:a:fedoraproject:389_directory_server:1.2.6
-
cpe:2.3:a:fedoraproject:389_directory_server:1.2.6.1
-
cpe:2.3:a:fedoraproject:389_directory_server:1.2.7
-
cpe:2.3:a:hp:hp-ux_directory_server:*
-
cpe:2.3:a:redhat:directory_server:8.0
-
cpe:2.3:a:redhat:redhat_directory_server:*