Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x before 8.8 SP8 Patch 9 Hotfix 2, and NetIQ eDirectory 9.x before 9.0.2 Hotfix 2 (9.0.2.2) use the deprecated MD5 hashing algorithm in a communications certificate.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HNetiq Edirectory
APPNetiq9.09.0.19.0.2Netiq Imanager
APPNetiq3.03.0.13.0.2Novell Edirectory
APPNovell≤ 8.8Novell Imanager
APPNovell≤ 2.7
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References
Related vulnerabilities
CVE-2017-7432CRITICAL9.8PL ✓same product
Podatność na upload webshell w Novell/NetIQ iManager
CVE-2008-5038CRITICAL9.8PL ✓same product
Use-after-free w Novell eDirectory — RCE przez protokół NCP
CVE-2002-2119CRITICAL9.8PL ✓same product
Novell eDirectory — brak rozróżniania wielkości liter w hasłach
CVE-2022-38758HIGH7.2same product
Cross-site Scripting (XSS) vulnerability in NetIQ iManager prior to version 3.2.6 allows attacker to execute m...
CVE-2017-7429HIGH8.8same product
The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload...