PT-2001-1818 · Netscape · Netscape Admin Server+1

Published

2001-07-27

·

Updated

2017-12-19

·

CVE-2001-0620

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: iPlanet Calendar Server version 5.0p2 and earlier
Description: The issue allows a local attacker to gain access to the Netscape Admin Server (NAS) LDAP database and read arbitrary files. This is achieved by obtaining the cleartext administrator username and password from the configuration file, which has insecure permissions.
Recommendations: For iPlanet Calendar Server version 5.0p2 and earlier, consider restricting access to the configuration file to prevent unauthorized users from obtaining the administrator credentials. As a temporary workaround, change the permissions of the configuration file to secure it and limit access to authorized personnel only.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-0620

Affected Products

Netscape Admin Server
Iplanet Calendar Server