PT-2004-3623 · Apache+1 · Apache+2

Publicado

2004-12-31

·

Atualizado

2017-07-29

·

CVE-2004-2734

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Novell NetWare 6.5
Description The issue concerns an inconsistency in the webadmin-apache.conf file within Novell Web Manager, where an uppercase Alias tag is used with a lowercase directory tag for a volume. This inconsistency allows remote attackers to bypass access control, specifically to the WEB-INF folder.
Recommendations For Novell NetWare 6.5, ensure consistency in the case of directory tags in the webadmin-apache.conf file to prevent access control bypass. As a temporary workaround, consider restricting access to the WEB-INF folder until the configuration issue is resolved.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2004-2734

Produtos afetados

Apache
Novell Netware 6.5
Novell Web Manager