SUSE Lifecycle Management Server before 1.1 uses world readable postgres credentials, which allows local users to obtain sensitive information via unspecified vectors.Referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/95697http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00005.html