CVE-2009-4879: Medium severity Novell Access Manager vulnerability
Published May 26, 2010
·Updated
The Identity Server in Novell Access Manager before 3.1 SP1 allows attackers with disabled Active Directory accounts to authenticate using X.509 authentication, which bypasses intended access restrictions.
Affected Software
2 affected components
Novell Access Manager<=3.1
Novell Access Manager=3
Event History
May 26, 2010
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-4879?
CVE-2009-4879 has a high severity rating as it allows unauthorized access through disabled Active Directory accounts.
2
How do I fix CVE-2009-4879?
To fix CVE-2009-4879, upgrade Novell Access Manager to version 3.1 SP1 or later.
3
What kind of attack does CVE-2009-4879 enable?
CVE-2009-4879 enables attackers to authenticate and gain access to systems despite having disabled Active Directory accounts.
4
Which versions of Novell Access Manager are affected by CVE-2009-4879?
Versions of Novell Access Manager prior to 3.1 SP1 are affected by CVE-2009-4879.
5
Can X.509 authentication be exploited in CVE-2009-4879?
Yes, CVE-2009-4879 exploits X.509 authentication to bypass access restrictions for disabled accounts.