PT-2001-1818 · Netscape · Netscape Admin Server+1
Publicado
2001-07-27
·
Atualizado
2017-12-19
·
CVE-2001-0620
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
iPlanet Calendar Server version 5.0p2 and earlier
Description:
The issue allows a local attacker to gain access to the Netscape Admin Server (NAS) LDAP database and read arbitrary files. This is achieved by obtaining the cleartext administrator
username and password from the configuration file, which has insecure permissions.Recommendations:
For iPlanet Calendar Server version 5.0p2 and earlier, consider restricting access to the configuration file to prevent unauthorized users from obtaining the administrator credentials. As a temporary workaround, change the permissions of the configuration file to secure it and limit access to authorized personnel only.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Netscape Admin Server
Iplanet Calendar Server