CVE-2008-0926
published 2008-03-28CVE-2008-0926: The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on client-side authentication, which allows…
PriorityP264high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
58.18%
99.0th percentile
The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on client-side authentication, which allows remote attackers to bypass authentication via requests for /SOAP URIs, and cause a denial of service (daemon shutdown) or read arbitrary files. NOTE: it was later reported that 8.7.3.10 (aka 8.7.3 SP10) is also affected.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| novell | edirectory | <= 8.7.3.10 | — |
| novell | edirectory | — | — |
| novell | edirectory | — | — |
| novell | edirectory | — | — |
| novell | edirectory | — | — |
| novell | edirectory | — | — |
| novell | edirectory | — | — |
| novell | edirectory | — | — |
| novell | edirectory | — | — |
| novell | edirectory | — | — |
| novell | edirectory | — | — |
| novell | edirectory | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for unauthenticated HTTP/HTTPS requests targeting the /SOAP URI path on eDirectory eMBox service ports (8008, 8009, 80, 443, 8030); legitimate access should require authentication. ↗
- →Alert on SOAP requests invoking eMBox actions such as STOP_SERVICE or SET_LOGFILE from unauthenticated or unexpected sources, as these can cause daemon shutdown or arbitrary file reads. ↗
- →Detect execution or presence of eMBoxClient.jar on hosts, which is the client-side tool used to exploit this vulnerability against eDirectory. ↗
- ·The vulnerability is rooted in client-side authentication design of the eMBox SOAP interface; the service itself does not enforce server-side authentication, meaning network-level controls (firewall rules blocking ports 8008, 8009, 8030) are the primary mitigation until patching. ↗
- ·Affected versions include eDirectory 8.7.3.9 and earlier AND 8.7.3.10 (SP10), as well as 8.8.x before 8.8.2; version checks must account for the SP10 branch being vulnerable despite its higher patch number. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m2rf-mf3r-f836: Unspecified vulnerability in eMBox in Novell eDirectory 8
ghsa_unreviewed·2022-05-02·CVSS 7.5
CVE-2010-0666 [HIGH] GHSA-m2rf-mf3r-f836: Unspecified vulnerability in eMBox in Novell eDirectory 8
Unspecified vulnerability in eMBox in Novell eDirectory 8.8 SP5 Patch 2 and earlier allows remote attackers to cause a denial of service (crash) via unknown a crafted SOAP request, a different issue than CVE-2008-0926.
GHSA
GHSA-2rcj-xx33-m8j8: The SOAP interface to the eMBox module in Novell eDirectory 8
ghsa_unreviewed·2022-05-01
CVE-2008-0926 [HIGH] CWE-287 GHSA-2rcj-xx33-m8j8: The SOAP interface to the eMBox module in Novell eDirectory 8
The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on client-side authentication, which allows remote attackers to bypass authentication via requests for /SOAP URIs, and cause a denial of service (daemon shutdown) or read arbitrary files. NOTE: it was later reported that 8.7.3.10 (aka 8.7.3 SP10) is also affected.
No detection rules found.
Exploit-DB
Novell eDirectory 8.x - eMBox Utility 'edirutil' Command
exploitdb·2008-03-25
CVE-2008-0926 Novell eDirectory 8.x - eMBox Utility 'edirutil' Command
Novell eDirectory 8.x - eMBox Utility 'edirutil' Command
---
source: https://www.securityfocus.com/bid/28441/info
Novell eDirectory is prone to an unspecified vulnerability that can result in unauthorized file access or a denial of service.
Unauthenticated attackers can exploit this issue.
This issue affects eDirectory 8.8 (and earlier) as well as 8.7.3.9 (and earlier).
java -cp eMBoxClient.jar embox -i
login -s edir_ip_address -p port (port can be 8008, 8009, 80, 443, 8030)
Metasploit
Novell eDirectory eMBox Unauthenticated File Access
metasploit
Novell eDirectory eMBox Unauthenticated File Access
Novell eDirectory eMBox Unauthenticated File Access
This module will access Novell eDirectory's eMBox service and can run the following actions via the SOAP interface: GET_DN, READ_LOGS, LIST_SERVICES, STOP_SERVICE, START_SERVICE, SET_LOGFILE.
No writeups or analysis indexed.
http://secunia.com/advisories/29527http://www.securityfocus.com/archive/1/491621/100/0/threadedhttp://www.securityfocus.com/bid/28441http://www.securitytracker.com/id?1019691http://www.vupen.com/english/advisories/2008/0988/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/41426https://secure-support.novell.com/KanisaPlatform/Publishing/876/3866911_f.SAL_Public.htmlhttp://secunia.com/advisories/29527http://www.securityfocus.com/archive/1/491621/100/0/threadedhttp://www.securityfocus.com/bid/28441http://www.securitytracker.com/id?1019691http://www.vupen.com/english/advisories/2008/0988/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/41426https://secure-support.novell.com/KanisaPlatform/Publishing/876/3866911_f.SAL_Public.html
2008-03-28
Published