Novell Open Enterprise Server DSfW Domain Group Policy Object Security Bypass Vulnerability
BID:50170
Info
Novell Open Enterprise Server DSfW Domain Group Policy Object Security Bypass Vulnerability
| Bugtraq ID: | 50170 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 17 2011 12:00AM |
| Updated: | Oct 17 2011 12:00AM |
| Credit: | Novell |
| Vulnerable: |
Novell Open Enterprise Server 2 Linux Support Pack |
| Not Vulnerable: | |
Discussion
Novell Open Enterprise Server DSfW Domain Group Policy Object Security Bypass Vulnerability
Novell Open Enterprise Server is prone to a security-bypass vulnerability.
Attackers can exploit this issue to bypass certain security restrictions and perform unauthorized actions; this may aid in further attacks.
Note: To exploit this issue, the 'DSfW' domain must be hosted by the affected domain controllers.
Novell Open Enterprise Server 2 SP3 is affected.
Novell Open Enterprise Server is prone to a security-bypass vulnerability.
Attackers can exploit this issue to bypass certain security restrictions and perform unauthorized actions; this may aid in further attacks.
Note: To exploit this issue, the 'DSfW' domain must be hosted by the affected domain controllers.
Novell Open Enterprise Server 2 SP3 is affected.
Exploit / POC
Novell Open Enterprise Server DSfW Domain Group Policy Object Security Bypass Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
Novell Open Enterprise Server DSfW Domain Group Policy Object Security Bypass Vulnerability
Solution:
The vendor has released an update. Please see the references for details.
Solution:
The vendor has released an update. Please see the references for details.
References
Novell Open Enterprise Server DSfW Domain Group Policy Object Security Bypass Vulnerability
References:
References: