Novell Access Manager Identity Server X.509 Authentication Security Bypass Vulnerability
BID:40427
Info
Novell Access Manager Identity Server X.509 Authentication Security Bypass Vulnerability
| Bugtraq ID: | 40427 |
| Class: | Access Validation Error |
| CVE: |
CVE-2009-4879 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 17 2009 12:00AM |
| Updated: | Jul 17 2009 12:00AM |
| Credit: | Novell |
| Vulnerable: |
Novell Access Manager 3.1 Novell Access Manager 3 |
| Not Vulnerable: |
Novell Access Manager 3.1 SP1 |
Discussion
Novell Access Manager Identity Server X.509 Authentication Security Bypass Vulnerability
Novell Access Manager is prone to a security-bypass vulnerability.
Attackers can exploit this issue to bypass security restrictions and gain access to the system; this may aid in further attacks.
The vulnerability affects versions prior to Novell Access Manager 3.1 SP1.
Novell Access Manager is prone to a security-bypass vulnerability.
Attackers can exploit this issue to bypass security restrictions and gain access to the system; this may aid in further attacks.
The vulnerability affects versions prior to Novell Access Manager 3.1 SP1.
Exploit / POC
Novell Access Manager Identity Server X.509 Authentication Security Bypass Vulnerability
Attackers can exploit this issue using readily available tools.
Attackers can exploit this issue using readily available tools.
Solution / Fix
Novell Access Manager Identity Server X.509 Authentication Security Bypass Vulnerability
Solution:
The vendor has released an update. Please see the references for details.
Solution:
The vendor has released an update. Please see the references for details.
References
Novell Access Manager Identity Server X.509 Authentication Security Bypass Vulnerability
References:
References:
- Novell Access Manager 3.1 SP1 Readme (Novell)
- Novell Access Manager Homepage (Novell)