5

CVE-2009-3862

The NDSD process in Novell eDirectory 8.7.3 before 8.7.3.10 ftf2 and eDirectory 8.8 before 8.8.5 ftf1 does not properly handle certain LDAP search requests, which allows remote attackers to cause a denial of service (application hang) via a search request with a NULL BaseDN value.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NovellEdirectory Version8.7.3
NovellEdirectory Version8.7.3 Updatesp2 Editionwindows
NovellEdirectory Version8.7.3 Updatesp3 Editionwindows
NovellEdirectory Version8.7.3 Updatesp4 Editionwindows
NovellEdirectory Version8.7.3 Updatesp5 Editionwindows
NovellEdirectory Version8.7.3 Updatesp6 Editionwindows
NovellEdirectory Version8.7.3 Updatesp7 Editionwindows
NovellEdirectory Version8.7.3 Updatesp8 Editionwindows
NovellEdirectory Version8.7.3 Updatesp9 Editionwindows
NovellEdirectory Version8.7.3.8
NovellEdirectory Version8.7.3.9
NovellEdirectory Version8.8
NovellEdirectory Version8.8 Updatesp1
NovellEdirectory Version8.8 Updatesp2
NovellEdirectory Version8.8 Updatesp3
NovellEdirectory Version8.8 Updatesp4
NovellEdirectory Version8.8.1
NovellEdirectory Version8.8.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.67% 0.689
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.