CVE-2006-2185: Medium severity Novell NetWare FTP Server vulnerability
Published May 22, 2006
·Updated
PORTAL.NLM in Novell Netware 6.5 SP5 writes the username and password in cleartext to the abend.log log file when the groupOperationsMethod function fails, which allows context-dependent attackers to gain privileges.
Affected Software
1 affected component
Novell NetWare FTP Server=6.5-sp5
Remediation
Patch Available
Event History
May 22, 2006
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2185?
CVE-2006-2185 is considered to have a high severity due to the exposure of sensitive credentials.
2
How do I fix CVE-2006-2185?
The recommended fix for CVE-2006-2185 is to upgrade to a patched version of Novell NetWare that addresses this logging issue.
3
What software is affected by CVE-2006-2185?
CVE-2006-2185 affects Novell Netware version 6.5 SP5.
4
What type of vulnerability is CVE-2006-2185?
CVE-2006-2185 is a credential exposure vulnerability that allows attackers to access usernames and passwords.
5
Can CVE-2006-2185 allow unauthorized access?
Yes, CVE-2006-2185 can allow context-dependent attackers to gain unauthorized access due to the exposure of login credentials.