PT-2004-3623 · Apache+1 · Apache+2
Published
2004-12-31
·
Updated
2017-07-29
·
CVE-2004-2734
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Novell NetWare 6.5
Description
The issue concerns an inconsistency in the
webadmin-apache.conf file within Novell Web Manager, where an uppercase Alias tag is used with a lowercase directory tag for a volume. This inconsistency allows remote attackers to bypass access control, specifically to the WEB-INF folder.Recommendations
For Novell NetWare 6.5, ensure consistency in the case of directory tags in the
webadmin-apache.conf file to prevent access control bypass. As a temporary workaround, consider restricting access to the WEB-INF folder until the configuration issue is resolved.Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache
Novell Netware 6.5
Novell Web Manager