CVE-2007-1309: Critical severity Novell Access Manager vulnerability
Published Mar 7, 2007
·Updated
Novell Access Management 3 SSLVPN Server allows remote authenticated users to bypass VPN restrictions by making policy.txt read-only, disconnecting, then manually modifying policy.txt.
Affected Software
1 affected component
Novell Access Manager=3
Remediation
Patch Available
Patch Available
Event History
Mar 7, 2007
CVE Published
12:19 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-1309?
CVE-2007-1309 has a medium severity rating due to potential impacts on VPN security.
2
How do I fix CVE-2007-1309?
To fix CVE-2007-1309, ensure that proper permissions are set for the policy.txt file and restrict user access to modify it.
3
Who is affected by CVE-2007-1309?
CVE-2007-1309 affects users of Novell Access Manager version 3.
4
What type of vulnerability is CVE-2007-1309?
CVE-2007-1309 is a privilege escalation vulnerability that can allow authenticated users to bypass VPN restrictions.
5
Can CVE-2007-1309 be exploited remotely?
Yes, CVE-2007-1309 can be exploited remotely by authenticated users of the Novell Access Management SSLVPN Server.