CVE-2024-11604
Received
Received - Intake
Sensitive Information Exposure via Log Files in OpenText IDM SCIM Driver
Publication date: 2026-03-27
Last updated on: 2026-03-27
Assigner: OpenText
Description
Description
Insertion of Sensitive Information into Log File vulnerability in the SCIM Driver module in OpenText IDM Driver and Extensions on Windows, Linux, 64 bit allows authenticated local users to obtain sensitive information via access to log files. This issue affects IDM SCIM Driver: 1.0.0.0000 through 1.0.1.0300 and 1.1.0.0000.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| opentext | idm_scim_driver | From 1.0.0 (inc) to 1.0.1.0300 (inc) |
| opentext | idm_scim_driver | 1.1.0 |
| opentext | idm_scim_driver | 1.0.1 |
| opentext | idm_scim_driver | From 1.0.0.0000 (inc) to 1.0.1.0300 (inc) |
| opentext | idm_scim_driver | 1.1.0.0000 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-532 | The product writes sensitive information to a log file. |