Lucene search

K
cve[email protected]CVE-2008-5696
HistoryDec 19, 2008 - 6:30 p.m.

CVE-2008-5696

2008-12-1918:30:00
CWE-255
web.nvd.nist.gov
28
cve-2008-5696
novell
netware
support pack 8
oes2 linux
nds
apacheadmin
console
remote attackers
apache http server
security vulnerability

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

6.9 Medium

AI Score

Confidence

Low

0.024 Low

EPSS

Percentile

90.1%

Novell NetWare 6.5 before Support Pack 8, when an OES2 Linux server is installed into the NDS tree, does not require a password for the ApacheAdmin console, which allows remote attackers to reconfigure the Apache HTTP Server via console operations.

Affected configurations

NVD
Node
novellnetwareRange6.5sp7
OR
novellnetwareMatch6.5
OR
novellnetwareMatch6.5sp1
OR
novellnetwareMatch6.5sp1.1a
OR
novellnetwareMatch6.5sp1.1b
OR
novellnetwareMatch6.5sp2
OR
novellnetwareMatch6.5sp3
OR
novellnetwareMatch6.5sp4
OR
novellnetwareMatch6.5sp5
OR
novellnetwareMatch6.5sp6
CPENameOperatorVersion
novell:netwarenovell netwarele6.5

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

6.9 Medium

AI Score

Confidence

Low

0.024 Low

EPSS

Percentile

90.1%

Related for CVE-2008-5696