EMC Unisphere for VMAX before 1.6.1.6, when using an unspecified level of debug logging in LDAP configurations, allows local users to discover the cleartext LDAP bind password by reading the console.
CVSS Vector
AV:L/AC:M/Au:N/C:P/I:N/A:NDell Emc Unisphere
APPDell1.01.11.5≤ 1.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2018-1183CRITICAL9.8PL ✓same product
XXE Injection w komponentach ECOM systemów Dell EMC (RCE/ujawnienie danych)
CVE-2017-14375CRITICAL9.8PL ✓same product
Pominięcie uwierzytelnienia w EMC Unisphere, Solutions Enabler, VASA i VMAX eManagement
CVE-2016-6646CRITICAL9.8PL ✓same product
RCE w EMC Unisphere i Solutions Enabler Virtual Appliance przez vApp Manager
CVE-2016-0889CRITICAL9.8PL ✓same product
Zapis do dowolnych plików w EMC Unisphere for VMAX Virtual Appliance
CVE-2016-6645HIGH8.8same product
The vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions E...