CVE-2010-3282 is a low-severity vulnerability affecting 389 Directory Server (before 1.2.7.1) and HP-UX Directory Server (before B.08.10.03). When audit logging is enabled, the Directory Manager password (nsslapd-rootpw) is logged in cleartext during password changes, allowing local users to potentially access sensitive information by reading the logs. The CVSS score is 3.3 (Low), indicating a local attack vector with low complexity and a low impact on confidentiality. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< b.08.10.03CPE matchmatch criteria | cpe:2.3:a:hp:hp-ux_directory_server:*:*:*:*:*:*:*:* | ||
< b.08.00.02CPE matchmatch criteria | cpe:2.3:a:redhat:redhat_directory_server:*:*:*:*:*:hp-ux:*:* | ||
< 1.2.7.1CPE matchmatch criteria | cpe:2.3:a:fedoraproject:389_directory_server:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:a:redhat:directory_server:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.