iPlanet Calendar Server Plaintext Admin Password Vulnerability
BID:2630
Info
iPlanet Calendar Server Plaintext Admin Password Vulnerability
| Bugtraq ID: | 2630 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Unknown |
| Local: | Yes |
| Published: | Apr 18 2001 12:00AM |
| Updated: | Apr 18 2001 12:00AM |
| Credit: | Reported to bugtraq by Adam Laurie <[email protected]> on 18 Apr 2001. |
| Vulnerable: |
iPlanet Calendar Server 5.0 p2 iPlanet Calendar Server 5.0 p1 iPlanet Calendar Server 2.1 p3 iPlanet Calendar Server 2.1 p2 iPlanet Calendar Server 2.1 p1 iPlanet Calendar Server 2.1 |
| Not Vulnerable: | |
Discussion
iPlanet Calendar Server Plaintext Admin Password Vulnerability
iPlanet's Calendar Server provides enterprise-wide calendar/planner sharing services.
Versions of Calendar Server store the username and password for the NAS LDAP database's adminstration account in a file which can be read by arbitrary users.
The NAS LDAP database stores sensitive systsem information such as userids, passwords, access control lists and authentication certificates.
If obtained by a malicious user, this data could be used to effect a wide array of compromises of the host.
iPlanet's Calendar Server provides enterprise-wide calendar/planner sharing services.
Versions of Calendar Server store the username and password for the NAS LDAP database's adminstration account in a file which can be read by arbitrary users.
The NAS LDAP database stores sensitive systsem information such as userids, passwords, access control lists and authentication certificates.
If obtained by a malicious user, this data could be used to effect a wide array of compromises of the host.
Exploit / POC
iPlanet Calendar Server Plaintext Admin Password Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
iPlanet Calendar Server Plaintext Admin Password Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
iPlanet Calendar Server Plaintext Admin Password Vulnerability
References:
References:
- iPlanet Calendar Server homepage (iPlanet)