CVE-2004-2104: Medium severity Novell NetWare FTP Server vulnerability
Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server information, including the internal IP address, via a direct request to (1) snoop.jsp, (2) SnoopServlet, (3) env.bas, or (4) lcgitest.nlm.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2104?
CVE-2004-2104 is classified as a moderate vulnerability due to the potential exposure of sensitive server information.
How do I fix CVE-2004-2104?
To fix CVE-2004-2104, you should restrict access to the identified JSP and servlet files or upgrade to a newer version of Novell NetWare.
What versions of Novell NetWare are affected by CVE-2004-2104?
CVE-2004-2104 affects Novell NetWare versions 5.1 and 6.0.
What kind of information can be exposed through CVE-2004-2104?
CVE-2004-2104 can expose sensitive server information, including internal IP addresses, to remote attackers.
Is CVE-2004-2104 a remote code execution vulnerability?
No, CVE-2004-2104 is not a remote code execution vulnerability, but it allows information disclosure.