Novell eDirectory eMBoxClient.JAR Information Disclosure Vulnerability
BID:19499
CVE-2006-4186 |Info
Novell eDirectory eMBoxClient.JAR Information Disclosure Vulnerability
| Bugtraq ID: | 19499 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Aug 11 2006 12:00AM |
| Updated: | Aug 14 2006 10:15PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Novell eDirectory 8.7.3 .8 pre-SP9 |
| Not Vulnerable: | |
Discussion
Novell eDirectory eMBoxClient.JAR Information Disclosure Vulnerability
The Novell eDirectory Server is prone to an information-disclosure vulnerability because the application fails to protect sensitive information from unprivileged users.
The flaw presents itself in eDirectory version 8.7.3.8; other versions may also be affected.
The Novell eDirectory Server is prone to an information-disclosure vulnerability because the application fails to protect sensitive information from unprivileged users.
The flaw presents itself in eDirectory version 8.7.3.8; other versions may also be affected.
Exploit / POC
Novell eDirectory eMBoxClient.JAR Information Disclosure Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Novell eDirectory eMBoxClient.JAR Information Disclosure Vulnerability
Solution:
Novell has released an advisory and a fix to address this issue. Please see the referenced advisory for more information.
Solution:
Novell has released an advisory and a fix to address this issue. Please see the referenced advisory for more information.
References
Novell eDirectory eMBoxClient.JAR Information Disclosure Vulnerability
References:
References: