Novell eDirectory NMAS Authentication Bypass Vulnerability
BID:14419
Info
Novell eDirectory NMAS Authentication Bypass Vulnerability
| Bugtraq ID: | 14419 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 29 2005 12:00AM |
| Updated: | Jul 29 2005 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Novell eDirectory 8.7.1 SU1 Novell eDirectory 8.7.1 Novell eDirectory 8.7 Novell eDirectory 8.6.2 Novell eDirectory 8.5.27 Novell eDirectory 8.5.12 a Novell eDirectory 8.5 Novell eDirectory 8.0 |
| Not Vulnerable: | |
Discussion
Novell eDirectory NMAS Authentication Bypass Vulnerability
Novell eDirectory is prone to an issue that could result in unauthorized access to a user's account.
An unauthorized attacker can change a user's password because the application fails to verify responses to challenge questions.
eDirectory NMAS versions prior to 2.3.8 are affected.
Novell eDirectory is prone to an issue that could result in unauthorized access to a user's account.
An unauthorized attacker can change a user's password because the application fails to verify responses to challenge questions.
eDirectory NMAS versions prior to 2.3.8 are affected.
Exploit / POC
Novell eDirectory NMAS Authentication Bypass Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Novell eDirectory NMAS Authentication Bypass Vulnerability
Solution:
Novell has released Technical Information Document TID2971485 including NMAS 2.3.8 to address this issue. Please see the referenced document for more information.
Solution:
Novell has released Technical Information Document TID2971485 including NMAS 2.3.8 to address this issue. Please see the referenced document for more information.
References
Novell eDirectory NMAS Authentication Bypass Vulnerability
References:
References: