CVE-2016-9167: High severity micro focus netiq edirectory vulnerability
Published Mar 23, 2017
·Updated
NDSD in Novell eDirectory before 9.0.2 did not calculate ACLs on LDAP objects across partition boundaries correctly, which could lead to a privilege escalation by modifying user attributes that would otherwise be filtered by an ACL.
Affected Software
1 affected component
Novell eDirectory<=9.0.1
Event History
Mar 23, 2017
CVE Published
via MITRE·06:36 AM
Data Sourced
via MITRE·06:36 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-9167?
CVE-2016-9167 is considered a medium severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2016-9167?
To fix CVE-2016-9167, upgrade Novell eDirectory to version 9.0.2 or later.
3
What can exploit CVE-2016-9167?
CVE-2016-9167 can be exploited by unauthorized users who can modify LDAP objects across partition boundaries.
4
What are the impacts of CVE-2016-9167 if exploited?
If exploited, CVE-2016-9167 can allow an attacker to modify user attributes and bypass access control lists.
5
Which versions of Novell eDirectory are affected by CVE-2016-9167?
Novell eDirectory versions prior to 9.0.2 are affected by CVE-2016-9167.