CVE-2018-12461
Published Jul 10, 2018Fixed issues with NetIQ eDirectory prior to 9.1.1 when checking certificate revocation.
Vendor/product archive
5 CVEs tagged to netiq / edirectory — 0 Critical, 2 High, 1 Medium, 2 Low, 0 Unrated.
Fixed issues with NetIQ eDirectory prior to 9.1.1 when checking certificate revocation.
Addresses denial of service attack to eDirectory versions prior to 9.1.
NetIQ eDirectory before 9.0 SP4 did not enforce login restrictions when "ebaclient" was used, allowing unpermitted access to eDirectory services.
The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated attackers to execute J…
Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x before 8.8 SP8 Patch 9 Hotfix 2, and NetIQ eDirectory 9.x before 9.0.2 Hotfix 2…