PT-2001-1818 · Netscape · Netscape Admin Server+1
Published
2001-07-27
·
Updated
2017-12-19
·
CVE-2001-0620
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
iPlanet Calendar Server version 5.0p2 and earlier
Description:
The issue allows a local attacker to gain access to the Netscape Admin Server (NAS) LDAP database and read arbitrary files. This is achieved by obtaining the cleartext administrator
username and password from the configuration file, which has insecure permissions.Recommendations:
For iPlanet Calendar Server version 5.0p2 and earlier, consider restricting access to the configuration file to prevent unauthorized users from obtaining the administrator credentials. As a temporary workaround, change the permissions of the configuration file to secure it and limit access to authorized personnel only.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netscape Admin Server
Iplanet Calendar Server