HIGH🇵🇱 Wersja polska

CVE-2017-5186

CVSS 7.5v3.0pub. 2017-04-27upd. 2026-05-13

Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x before 8.8 SP8 Patch 9 Hotfix 2, and NetIQ eDirectory 9.x before 9.0.2 Hotfix 2 (9.0.2.2) use the deprecated MD5 hashing algorithm in a communications certificate.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Netiq Edirectory

    APP
    Netiq
    9.09.0.19.0.2
  • Netiq Imanager

    APP
    Netiq
    3.03.0.13.0.2
  • Novell Edirectory

    APP
    Novell
    ≤ 8.8
  • Novell Imanager

    APP
    Novell
    ≤ 2.7
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2017-7432CRITICAL9.8PL ✓same product

Podatność na upload webshell w Novell/NetIQ iManager

CVE-2008-5038CRITICAL9.8PL ✓same product

Use-after-free w Novell eDirectory — RCE przez protokół NCP

CVE-2002-2119CRITICAL9.8PL ✓same product

Novell eDirectory — brak rozróżniania wielkości liter w hasłach

CVE-2022-38758HIGH7.2same product

Cross-site Scripting (XSS) vulnerability in NetIQ iManager prior to version 3.2.6 allows attacker to execute m...

CVE-2017-7429HIGH8.8same product

The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload...