Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x before 8.8 SP8 Patch 9 Hotfix 2, and NetIQ eDirectory 9.x before 9.0.2 Hotfix 2 (9.0.2.2) use the deprecated MD5 hashing algorithm in a communications certificate.
oryginał ENCVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HNetiq Edirectory
APPNetiq9.09.0.19.0.2Netiq Imanager
APPNetiq3.03.0.13.0.2Novell Edirectory
APPNovell≤ 8.8Novell Imanager
APPNovell≤ 2.7
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje
Powiązane podatności
CVE-2017-7432CRITICAL9.8PL ✓ten sam produkt
Podatność na upload webshell w Novell/NetIQ iManager
CVE-2008-5038CRITICAL9.8PL ✓ten sam produkt
Use-after-free w Novell eDirectory — RCE przez protokół NCP
CVE-2002-2119CRITICAL9.8PL ✓ten sam produkt
Novell eDirectory — brak rozróżniania wielkości liter w hasłach
CVE-2022-38758HIGH7.2ten sam produkt
Cross-site Scripting (XSS) vulnerability in NetIQ iManager prior to version 3.2.6 allows attacker to execute m...
CVE-2017-7429HIGH8.8ten sam produkt
The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload...