← Vulnerability feed

Vulnerability record · CVE-2010-3282 · published 9 January 2020

CVE-2010-3282: Hp-ux directory server cleartext storage of sensitive data vulnerability

Hp · Hp Ux Directory Server

389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when changing cn=config:nsslapd-rootpw, which might allow local users to obtain sensitive information by reading the log.

3.3 CVSS 3.1 Low EPSS 0.26% · top 83.3% CWE-312 · Cleartext storage of sensitive data
3.3CVSS 3.1 base score, v2 1.9
0.26%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when changing cn=config:nsslapd-rootpw, which might allow local users to obtain sensitive information by reading the log.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2010-3282 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-2928Redhat directory server memory buffer overflow vulnerabilityMultiple buffer overflows in the adminutil library in CGI applications in Red Hat Directory Server 7.1 before SP7 allow remote attackers to cause a d…EPSS 6.6%9.8CVE-2017-7551Fedoraproject 389 directory server error message information leak vulnerability389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different return codes r…EPSS 1.4%9.0CVE-2008-0892Redhat directory server improper input validation vulnerabilityThe replication monitor CGI script (repl-monitor-cgi.pl) in Red Hat Administration Server, as used by Red Hat Directory Server 8.0 EL4 and EL5, allow…EPSS 14%8.1CVE-2017-15135Fedoraproject 389 directory server improper authentication vulnerabilityIt was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly during th…EPSS 3.8%7.8CVE-2008-3283Fedora directory server vulnerabilityMultiple memory leaks in Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 and earlier allow rem…EPSS 2.9%7.5CVE-2026-15722Redhat directory server stack-based buffer overflow vulnerabilityA stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit c…EPSS 0.83%7.5CVE-2026-11770Redhat directory server ldap injection vulnerabilityA flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-c…EPSS 0.53%7.5CVE-2026-11788Redhat directory server null pointer dereference vulnerabilityA flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing…EPSS 0.56%

Source: NIST National Vulnerability Database (record CVE-2010-3282), CISA KEV, FIRST EPSS (scores of 2026-10-06). This page is refreshed as NVD updates the record.