CVE-2016-9166: High severity microfocus edirectory vulnerability
Published Mar 18, 2019
·Updated
NetIQ eDirectory versions prior to 9.0.2, under some circumstances, could be susceptible to downgrade of communication security.
Affected Software
3 affected components
Microfocus Netiq Edirectory<9.0
Microfocus Netiq Edirectory=9.0
Microfocus Netiq Edirectory=9.0-sp1
Event History
Mar 18, 2019
CVE Published
via MITRE·02:41 PM
Data Sourced
via MITRE·02:41 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-9166?
CVE-2016-9166 is considered a medium severity vulnerability due to the potential for downgrading communication security in affected versions of NetIQ eDirectory.
2
How do I fix CVE-2016-9166?
To fix CVE-2016-9166, you should upgrade NetIQ eDirectory to version 9.0.2 or later.
3
Which versions of NetIQ eDirectory are affected by CVE-2016-9166?
CVE-2016-9166 affects NetIQ eDirectory versions prior to 9.0.2, including version 9.0 and its service pack 1.
4
What kind of vulnerability is CVE-2016-9166?
CVE-2016-9166 is a communication security vulnerability that allows for a potential downgrade in security protocols.
5
Is there a workaround for CVE-2016-9166 if I cannot upgrade?
There are no specific workarounds for CVE-2016-9166; the best mitigation is to upgrade the affected software to a secure version.