Low severity3.3NVD Advisory· Published Jan 9, 2020· Updated Jun 16, 2026
CVE-2010-3282
CVE-2010-3282
Description
389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when changing cn=config:nsslapd-rootpw, which might allow local users to obtain sensitive information by reading the log.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9- cpe:2.3:a:fedoraproject:389_directory_server:*:*:*:*:*:*:*:*Range: <1.2.7.1
- cpe:2.3:a:hp:hp-ux_directory_server:*:*:*:*:*:*:*:*Range: <b.08.10.03
cpe:2.3:a:redhat:directory_server:8.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:redhat:directory_server:8.0:*:*:*:*:*:*:*
- (no CPE)range: =8.2
- (no CPE)range: before 1.2.7.1
- cpe:2.3:a:redhat:redhat_directory_server:*:*:*:*:*:hp-ux:*:*Range: <b.08.00.02
- Range: <B.08.10.03
- Range: <B.08.10.03
- Range: before B.08.10.03
Patches
Vulnerability mechanics
References
4- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- support.hpe.com/hpsc/doc/public/displaynvdVendor Advisory
- oval.mitre.org/repository/data/getDefnvdNot Applicable
- git.fedorahosted.org/cgit/389/ds.git/commit/nvdProduct
News mentions
0No linked articles in our index yet.