7.5
CVSSv2

CVE-2008-0926

Published: 28/03/2008 Updated: 15/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and previous versions, and 8.8.x prior to 8.8.2, relies on client-side authentication, which allows remote malicious users to bypass authentication via requests for /SOAP URIs, and cause a denial of service (daemon shutdown) or read arbitrary files. NOTE: it was later reported that 8.7.3.10 (aka 8.7.3 SP10) is also affected.

Vulnerable Product Search on Vulmon Subscribe to Product

novell edirectory 8.5.27

novell edirectory 8.6.2

novell edirectory 8.7

novell edirectory 8.8

novell edirectory

novell edirectory 8.7.1

novell edirectory 8.5

novell edirectory 8.5.12a

novell edirectory 8.7.3.8_presp9

novell edirectory 8.7.3.9

novell edirectory 8.7.3

novell edirectory 8.7.3.8

Exploits

source: wwwsecurityfocuscom/bid/28441/info Novell eDirectory is prone to an unspecified vulnerability that can result in unauthorized file access or a denial of service Unauthenticated attackers can exploit this issue This issue affects eDirectory 88 (and earlier) as well as 8739 (and earlier) java -cp eMBoxClientjar embox -i l ...