CVE-2008-5696: Critical severity Novell NetWare FTP Server vulnerability
Novell NetWare 6.5 before Support Pack 8, when an OES2 Linux server is installed into the NDS tree, does not require a password for the ApacheAdmin console, which allows remote attackers to reconfigure the Apache HTTP Server via console operations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Novell NetWare 6.5to a version that resolves this vulnerability.Fixed in Support Pack 8
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5696?
CVE-2008-5696 is considered a critical vulnerability due to its potential to allow remote unauthorized access to the ApacheAdmin console.
How does CVE-2008-5696 affect Novell NetWare versions?
CVE-2008-5696 affects Novell NetWare 6.5 and its various service pack versions prior to Support Pack 8.
How do I fix CVE-2008-5696?
To fix CVE-2008-5696, upgrade Novell NetWare to Support Pack 8 or later.
What are the potential impacts of CVE-2008-5696?
The impacts of CVE-2008-5696 include unauthorized reconfiguration of the Apache HTTP Server, potentially leading to further exploits.
What is the nature of the vulnerability in CVE-2008-5696?
CVE-2008-5696 is a security misconfiguration issue that does not require a password for accessing the ApacheAdmin console.