First published: Thu Mar 23 2017(Updated: )
NDSD in Novell eDirectory before 9.0.2 did not calculate ACLs on LDAP objects across partition boundaries correctly, which could lead to a privilege escalation by modifying user attributes that would otherwise be filtered by an ACL.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Microfocus eDirectory | <=9.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9167 is considered a medium severity vulnerability due to its potential for privilege escalation.
To fix CVE-2016-9167, upgrade Novell eDirectory to version 9.0.2 or later.
CVE-2016-9167 can be exploited by unauthorized users who can modify LDAP objects across partition boundaries.
If exploited, CVE-2016-9167 can allow an attacker to modify user attributes and bypass access control lists.
Novell eDirectory versions prior to 9.0.2 are affected by CVE-2016-9167.