Netiq Edirectory vulnerabilities
5 known vulnerabilities affecting netiq/edirectory.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH4
Vulnerabilities
Page 1 of 1
CVE-2018-12461HIGHCVSS 7.5v9.1.1≥ eDirectory 9.1.1, < 9.1.12018-07-10
CVE-2018-12461 [HIGH] CWE-295 CVE-2018-12461: Fixed issues with NetIQ eDirectory prior to 9.1.1 when checking certificate revocation.
Fixed issues with NetIQ eDirectory prior to 9.1.1 when checking certificate revocation.
cvelistv5nvd
CVE-2018-1346HIGHCVSS 7.5fixed in 9.1≥ prior to (9.1), < 9.12018-03-21
CVE-2018-1346 [HIGH] CVE-2018-1346: Addresses denial of service attack to eDirectory versions prior to 9.1.
Addresses denial of service attack to eDirectory versions prior to 9.1.
cvelistv5nvd
CVE-2017-9285CRITICALCVSS 9.8v9.0≥ unspecified, < 9.0 SP42018-03-02
CVE-2017-9285 [CRITICAL] CWE-284 CVE-2017-9285: NetIQ eDirectory before 9.0 SP4 did not enforce login restrictions when "ebaclient" was used, allowi
NetIQ eDirectory before 9.0 SP4 did not enforce login restrictions when "ebaclient" was used, allowing unpermitted access to eDirectory services.
cvelistv5nvd
CVE-2017-7429HIGHCVSS 8.8v8.8.8≥ unspecified, < 8.8.8 Patch 10 HF12018-03-02
CVE-2017-7429 [HIGH] CWE-434 CVE-2017-7429: The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused
The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated attackers to execute JSP applets on the iManager server.
cvelistv5nvd
CVE-2017-5186HIGHCVSS 7.5v9.0v9.0.1+1 more2017-04-27
CVE-2017-5186 [HIGH] CWE-327 CVE-2017-5186: Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x b
Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x before 8.8 SP8 Patch 9 Hotfix 2, and NetIQ eDirectory 9.x before 9.0.2 Hotfix 2 (9.0.2.2) use the deprecated MD5 hashing algorithm in a communications certificate.
nvd