CVE-2001-1233: Medium severity Novell Groupwise WebAccess vulnerability
Published Aug 14, 2001
·Updated
Netware Enterprise Web Server 5.1 running GroupWise WebAccess 5.5 with Novell Directory Services (NDS) enabled allows remote attackers to enumerate user names, group names and other system information by accessing ndsobj.nlm.
Affected Software
2 affected components
Novell Groupwise WebAccess=5.5
Novell Netware=5.1
Remediation
Patch Available
Event History
Aug 14, 2001
CVE Published
04:00 AM
May 3, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1233?
CVE-2001-1233 has a high severity rating due to its potential for unauthorized user enumeration.
2
How do I fix CVE-2001-1233?
To fix CVE-2001-1233, ensure that NDS is disabled or restrict access to ndsobj.nlm to prevent remote enumeration.
3
What software versions are affected by CVE-2001-1233?
CVE-2001-1233 affects Novell GroupWise WebAccess 5.5 and Novell NetWare 5.1.
4
What type of attack does CVE-2001-1233 enable?
CVE-2001-1233 enables remote attackers to enumerate usernames and group names within the affected systems.
5
Is CVE-2001-1233 still relevant today?
CVE-2001-1233 is considered relevant for legacy systems still running the affected software.