CVE-2017-5186: High severity micro focus netiq edirectory vulnerability
Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x before 8.8 SP8 Patch 9 Hotfix 2, and NetIQ eDirectory 9.x before 9.0.2 Hotfix 2 (9.0.2.2) use the deprecated MD5 hashing algorithm in a communications certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5186?
CVE-2017-5186 has a medium severity level due to the usage of the deprecated MD5 hashing algorithm in communications certificates.
How do I fix CVE-2017-5186?
To fix CVE-2017-5186, upgrade to the latest versions of Novell iManager or eDirectory that are patched against this vulnerability.
Which software versions are affected by CVE-2017-5186?
CVE-2017-5186 affects Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, and various versions of Novell and NetIQ eDirectory.
What consequences can arise from CVE-2017-5186?
Using the deprecated MD5 hashing algorithm in CVE-2017-5186 exposes data to potential tampering and impacts the integrity of secure communications.
Is there a workaround for CVE-2017-5186?
There are no documented workarounds for CVE-2017-5186; upgrading to a secure version is the recommended course of action.