cbcvebase.
CVE-2008-0926
published 2008-03-28

CVE-2008-0926: The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on client-side authentication, which allows…

PriorityP264high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
58.18%
99.0th percentile
The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on client-side authentication, which allows remote attackers to bypass authentication via requests for /SOAP URIs, and cause a denial of service (daemon shutdown) or read arbitrary files. NOTE: it was later reported that 8.7.3.10 (aka 8.7.3 SP10) is also affected.

Affected

12 ranges
VendorProductVersion rangeFixed in
novelledirectory<= 8.7.3.10
novelledirectory
novelledirectory
novelledirectory
novelledirectory
novelledirectory
novelledirectory
novelledirectory
novelledirectory
novelledirectory
novelledirectory
novelledirectory

Detection & IOCsextracted from sources · hover to see the quote

path/SOAP
port8008
port8009
port8030
  • Monitor for unauthenticated HTTP/HTTPS requests targeting the /SOAP URI path on eDirectory eMBox service ports (8008, 8009, 80, 443, 8030); legitimate access should require authentication.
  • Alert on SOAP requests invoking eMBox actions such as STOP_SERVICE or SET_LOGFILE from unauthenticated or unexpected sources, as these can cause daemon shutdown or arbitrary file reads.
  • Detect execution or presence of eMBoxClient.jar on hosts, which is the client-side tool used to exploit this vulnerability against eDirectory.
  • ·The vulnerability is rooted in client-side authentication design of the eMBox SOAP interface; the service itself does not enforce server-side authentication, meaning network-level controls (firewall rules blocking ports 8008, 8009, 8030) are the primary mitigation until patching.
  • ·Affected versions include eDirectory 8.7.3.9 and earlier AND 8.7.3.10 (SP10), as well as 8.8.x before 8.8.2; version checks must account for the SP10 branch being vulnerable despite its higher patch number.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.