Sun Java System Access Manager 6.3 2005Q1, 7.0 2005Q4, and 7.1; and OpenSSO Enterprise 8.0; when AMConfig.properties enables the debug flag, allows local users to discover cleartext passwords by reading debug files.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://osvdb.org/56815 | vdb entry |
http://www.securityfocus.com/bid/35963 | vdb entry |
http://secunia.com/advisories/36169 | third party advisory vendor advisory |
http://sunsolve.sun.com/search/document.do?assetkey=1-21-119465-16-1 | patch |
http://sunsolve.sun.com/search/document.do?assetkey=1-66-256668-1 | patch vendor advisory |
http://www.vupen.com/english/advisories/2009/2177 | vdb entry |