CVE-2004-2298: Medium severity Novell Internet Messaging System vulnerability
Novell Internet Messaging System (NIMS) 2.6 and 3.0, and NetMail 3.1 and 3.5, is installed with a default NMAP authentication credential, which allows remote attackers to read and write mail store data if the administrator does not change the credential by using the NMAP Credential Generator.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2298?
CVE-2004-2298 is classified as a high-severity vulnerability due to its potential for unauthorized access to mail store data.
How can I fix CVE-2004-2298?
To fix CVE-2004-2298, administrators should change the default NMAP authentication credential using the NMAP Credential Generator.
Which versions are affected by CVE-2004-2298?
CVE-2004-2298 affects Novell Internet Messaging System versions 2.6 and 3.0, as well as Novell NetMail versions 3.1 and 3.5.
Can CVE-2004-2298 be exploited remotely?
Yes, CVE-2004-2298 can be exploited remotely if the default credentials are not changed by the administrator.
What data can be compromised due to CVE-2004-2298?
CVE-2004-2298 allows remote attackers to read and write to the mail store data if the vulnerability is exploited.