NetIQ eDirectory authorization Bypass Vulnerability
Release date:
Updated on:
Affected Systems:
Netiq eDirectory 8.8.7.x
Netiq eDirectory 8.8.6.x
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2012-0430
NetIQ eDirectory is an LDAP directory.
Security Vulnerabilities in NetIQ eDirectory 8.8.6.x and 8.8.7.x allow remote attackers to obtain administrator cookies and bypass authorization checks.
<* Source: Positive Research
Link: http://web.nvd.nist.gov/view/vuln/detail? VulnId = CVE-2012-0430
Http://www.novell.com/support/kb/doc.php? Id = 3426981
Http://www.novell.com/support/kb/doc.php? Id = 7011538
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Netiq
-----
Netiq has released a Security Bulletin (7011538) and corresponding patches for this purpose:
7011538: Security Vulnerability: eDirectory Authorization mechanic Bypass
Link: http://www.novell.com/support/kb/doc.php? Id = 7011538
Patch download:
Http://download.novell.com/