First published: Wed Mar 07 2007(Updated: )
Novell Access Management 3 SSLVPN Server allows remote authenticated users to bypass VPN restrictions by making policy.txt read-only, disconnecting, then manually modifying policy.txt.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Micro Focus Access Manager | =3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1309 has a medium severity rating due to potential impacts on VPN security.
To fix CVE-2007-1309, ensure that proper permissions are set for the policy.txt file and restrict user access to modify it.
CVE-2007-1309 affects users of Novell Access Manager version 3.
CVE-2007-1309 is a privilege escalation vulnerability that can allow authenticated users to bypass VPN restrictions.
Yes, CVE-2007-1309 can be exploited remotely by authenticated users of the Novell Access Management SSLVPN Server.