First published: Fri Dec 31 2004(Updated: )
Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server information, including the internal IP address, via a direct request to (1) snoop.jsp, (2) SnoopServlet, (3) env.bas, or (4) lcgitest.nlm.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell NetWare | =5.1 | |
Novell NetWare | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2104 is classified as a moderate vulnerability due to the potential exposure of sensitive server information.
To fix CVE-2004-2104, you should restrict access to the identified JSP and servlet files or upgrade to a newer version of Novell NetWare.
CVE-2004-2104 affects Novell NetWare versions 5.1 and 6.0.
CVE-2004-2104 can expose sensitive server information, including internal IP addresses, to remote attackers.
No, CVE-2004-2104 is not a remote code execution vulnerability, but it allows information disclosure.