CVE-2016-9168: Input Validation
Published Mar 23, 2017
·Updated
A missing X-Frame-Options header in the NDS Utility Monitor in NDSD in Novell eDirectory before 9.0.2 could be used by remote attackers for clickjacking.
Affected Software
1 affected component
Novell eDirectory<=9.0.1
Event History
Mar 23, 2017
CVE Published
via MITRE·06:36 AM
Data Sourced
via MITRE·06:36 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-9168?
CVE-2016-9168 is classified as a medium severity vulnerability due to its potential for clickjacking attacks.
2
How do I fix CVE-2016-9168?
To fix CVE-2016-9168, you should upgrade Novell eDirectory to version 9.0.2 or later where the X-Frame-Options header is implemented.
3
What impact does CVE-2016-9168 have on my system?
CVE-2016-9168 allows remote attackers to perform clickjacking attacks, potentially compromising user actions within the affected application.
4
Is CVE-2016-9168 present in all versions of Novell eDirectory?
No, CVE-2016-9168 only affects Novell eDirectory versions prior to 9.0.2.
5
How can I verify if my system is vulnerable to CVE-2016-9168?
You can verify vulnerability by checking if the X-Frame-Options header is missing in the responses from the NDS Utility Monitor.