PT-2004-3623 · Apache+1 · Apache+2

Published

2004-12-31

·

Updated

2017-07-29

·

CVE-2004-2734

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Novell NetWare 6.5
Description The issue concerns an inconsistency in the webadmin-apache.conf file within Novell Web Manager, where an uppercase Alias tag is used with a lowercase directory tag for a volume. This inconsistency allows remote attackers to bypass access control, specifically to the WEB-INF folder.
Recommendations For Novell NetWare 6.5, ensure consistency in the case of directory tags in the webadmin-apache.conf file to prevent access control bypass. As a temporary workaround, consider restricting access to the WEB-INF folder until the configuration issue is resolved.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2004-2734

Affected Products

Apache
Novell Netware 6.5
Novell Web Manager