Novell eDirectory Role Based Services Insecure Role Permissions Vulnerability
BID:10223
Info
Novell eDirectory Role Based Services Insecure Role Permissions Vulnerability
| Bugtraq ID: | 10223 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 27 2004 12:00AM |
| Updated: | Apr 27 2004 12:00AM |
| Credit: | This issue was announced by the vendor. |
| Vulnerable: |
Novell eDirectory 8.7 |
| Not Vulnerable: | |
Discussion
Novell eDirectory Role Based Services Insecure Role Permissions Vulnerability
Novell eDirectory is prone to an issue that could result in unauthorized access to certain administrative rights.
The issue exists in the Role Based Services (RBS) component. The result of the issue is that users who have been added to certain Roles may inherit more administrative rights than explicitly required.
Novell eDirectory is prone to an issue that could result in unauthorized access to certain administrative rights.
The issue exists in the Role Based Services (RBS) component. The result of the issue is that users who have been added to certain Roles may inherit more administrative rights than explicitly required.
Exploit / POC
Novell eDirectory Role Based Services Insecure Role Permissions Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Novell eDirectory Role Based Services Insecure Role Permissions Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Novell eDirectory Role Based Services Insecure Role Permissions Vulnerability
References:
References: