First published: Mon Oct 02 2006(Updated: )
Apple Mac OS X 10.4 through 10.4.7, when the administrator clears the "Allow user to administer this computer" checkbox in System Preferences for a user, does not remove the user's account from the appserveradm or appserverusr groups, which still allows the user to manage WebObjects applications.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | =10.4.3 | |
macOS Yosemite | =10.4.1 | |
macOS Yosemite | =10.4.7 | |
macOS Yosemite | =10.4.4 | |
macOS Yosemite | =10.4 | |
macOS Yosemite | =10.4.6 | |
macOS Yosemite | =10.4.5 | |
macOS Yosemite | =10.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4387 is considered a moderate severity vulnerability due to the potential for unauthorized access to WebObjects applications.
To fix CVE-2006-4387, ensure that users are properly removed from the appserveradm and appserverusr groups when their administrative rights are revoked.
CVE-2006-4387 affects Apple Mac OS X versions 10.4 through 10.4.7.
The impact of CVE-2006-4387 is that unauthorized users may still manage WebObjects applications despite having their administrative permissions revoked.
While specific patches may be unavailable, users should upgrade their systems to a more secure version of macOS that addresses these vulnerabilities.