PT-2004-3623 · Apache+1 · Apache+2
Publicado
2004-12-31
·
Atualizado
2017-07-29
·
CVE-2004-2734
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Novell NetWare 6.5
Description
The issue concerns an inconsistency in the
webadmin-apache.conf file within Novell Web Manager, where an uppercase Alias tag is used with a lowercase directory tag for a volume. This inconsistency allows remote attackers to bypass access control, specifically to the WEB-INF folder.Recommendations
For Novell NetWare 6.5, ensure consistency in the case of directory tags in the
webadmin-apache.conf file to prevent access control bypass. As a temporary workaround, consider restricting access to the WEB-INF folder until the configuration issue is resolved.Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache
Novell Netware 6.5
Novell Web Manager