A vulnerability has been identified in Novell Identity Manager, which could be exploited by local attackers to gain knowledge of sensitive information. This issue is caused by an error in the Client Login Extension that writes the supplied username and password to a local file when a user logs in, which could be exploited by malicious users to gain unauthorized access to arbitrary accounts.