← back
CVE-2017-9278lowCWE-532

Avoid password disclosure via EBS event logging in the iManager Oracle driver

8Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 3.3epss 0.9%
exploitation probability
0.9%top 43% of all CVEs
observed exploitation
nono source reports it
The NetIQ Identity Manager Oracle EBS driver before 4.0.2.0 sent EBS logs containing the driver authentication password, potentially disclosing this to attackers able to read the EBS tables.
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N