First published: Mon Mar 18 2019(Updated: )
NetIQ eDirectory versions prior to 9.0.2, under some circumstances, could be susceptible to downgrade of communication security.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Microfocus eDirectory | <9.0 | |
Microfocus eDirectory | =9.0 | |
Microfocus eDirectory | =9.0-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9166 is considered a medium severity vulnerability due to the potential for downgrading communication security in affected versions of NetIQ eDirectory.
To fix CVE-2016-9166, you should upgrade NetIQ eDirectory to version 9.0.2 or later.
CVE-2016-9166 affects NetIQ eDirectory versions prior to 9.0.2, including version 9.0 and its service pack 1.
CVE-2016-9166 is a communication security vulnerability that allows for a potential downgrade in security protocols.
There are no specific workarounds for CVE-2016-9166; the best mitigation is to upgrade the affected software to a secure version.