Novell Groupwise Servlet Gateway Default Authentication Vulnerability
BID:3697
Info
Novell Groupwise Servlet Gateway Default Authentication Vulnerability
| Bugtraq ID: | 3697 |
| Class: | Configuration Error |
| CVE: |
CVE-2001-1195 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2001 12:00AM |
| Updated: | Jul 11 2009 09:06AM |
| Credit: | This vulnerability was submitted to BugTraq on December 15th, 2001 by Adam Gray <[email protected]>. |
| Vulnerable: |
Novell Groupwise Enhancement Pack 5.5 Novell Groupwise 6.0 |
| Not Vulnerable: | |
Discussion
Novell Groupwise Servlet Gateway Default Authentication Vulnerability
Novell Groupwise Servlet Gateway is a product that allows Java servlets to be run with NetWare, using Novell JVM for NetWare v1.1.7b and NetWare Enterprise Web Server.
A remote attacker may gain access to the Servlet Manager interface by entering the default username/password. The default username is "servlet" and the default password is "manager".
Novell Groupwise Servlet Gateway is a product that allows Java servlets to be run with NetWare, using Novell JVM for NetWare v1.1.7b and NetWare Enterprise Web Server.
A remote attacker may gain access to the Servlet Manager interface by entering the default username/password. The default username is "servlet" and the default password is "manager".
Exploit / POC
Novell Groupwise Servlet Gateway Default Authentication Vulnerability
Adam Gray <[email protected]> submitted the following example:
http://server/servlet/ServletManager
username servlet
password manager
Adam Gray <[email protected]> submitted the following example:
http://server/servlet/ServletManager
username servlet
password manager
Solution / Fix
Novell Groupwise Servlet Gateway Default Authentication Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Novell Groupwise Servlet Gateway Default Authentication Vulnerability
References:
References:
- Default Servlet Gateway password can allow (Novell)
- Novell Support (Novell)