Lucene search

K
cve[email protected]CVE-2009-4879
HistoryOct 03, 2022 - 4:24 p.m.

CVE-2009-4879

2022-10-0316:24:02
CWE-287
web.nvd.nist.gov
22
novell access manager
identity server
cve-2009-4879
x.509 authentication
active directory
access restrictions
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.7 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

33.0%

The Identity Server in Novell Access Manager before 3.1 SP1 allows attackers with disabled Active Directory accounts to authenticate using X.509 authentication, which bypasses intended access restrictions.

Affected configurations

NVD
Node
novellaccess_managerRange3.1
OR
novellaccess_managerMatch3

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.7 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

33.0%

Related for CVE-2009-4879