PT-2001-1818 · Netscape · Netscape Admin Server+1

Publicado

2001-07-27

·

Atualizado

2017-12-19

·

CVE-2001-0620

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: iPlanet Calendar Server version 5.0p2 and earlier
Description: The issue allows a local attacker to gain access to the Netscape Admin Server (NAS) LDAP database and read arbitrary files. This is achieved by obtaining the cleartext administrator username and password from the configuration file, which has insecure permissions.
Recommendations: For iPlanet Calendar Server version 5.0p2 and earlier, consider restricting access to the configuration file to prevent unauthorized users from obtaining the administrator credentials. As a temporary workaround, change the permissions of the configuration file to secure it and limit access to authorized personnel only.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-0620

Produtos afetados

Netscape Admin Server
Iplanet Calendar Server