Novell GroupWise 6 Post Office LDAP Authentication Bypass Vulnerability
BID:4154
Info
Novell GroupWise 6 Post Office LDAP Authentication Bypass Vulnerability
| Bugtraq ID: | 4154 |
| Class: | Design Error |
| CVE: |
CVE-2002-0303 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 20 2002 12:00AM |
| Updated: | Jul 11 2009 10:56AM |
| Credit: | This vulnerability was announced by Frank Bulk <[email protected]> on February 20, 2002. |
| Vulnerable: |
Novell Groupwise 6.0 |
| Not Vulnerable: | |
Discussion
Novell GroupWise 6 Post Office LDAP Authentication Bypass Vulnerability
GroupWise 6 is a directory service available from Novell. It is designed for use on the Microsoft Windows platforms.
When GroupWise is executed as any user, and the password field is left blank, it is possible to gain access to the account of the user without authenication. This problem occurs when GroupWise has been configured to use LDAP authentication and the security configuration of PostOffice leaves the LDAP username and password fields blank.
GroupWise 6 is a directory service available from Novell. It is designed for use on the Microsoft Windows platforms.
When GroupWise is executed as any user, and the password field is left blank, it is possible to gain access to the account of the user without authenication. This problem occurs when GroupWise has been configured to use LDAP authentication and the security configuration of PostOffice leaves the LDAP username and password fields blank.
Exploit / POC
Novell GroupWise 6 Post Office LDAP Authentication Bypass Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
Solution / Fix
Novell GroupWise 6 Post Office LDAP Authentication Bypass Vulnerability
Solution:
A patch is available:
Novell Groupwise 6.0
Solution:
A patch is available:
Novell Groupwise 6.0
-
Novell FGW62N4.EXE
http://support.novell.com/
References
Novell GroupWise 6 Post Office LDAP Authentication Bypass Vulnerability
References:
References:
- Novell Support (Novell)