First published: Fri Mar 02 2018(Updated: )
In Novell eDirectory before 9.0.3.1 the LDAP interface was not strictly enforcing cipher restrictions allowing weaker ciphers to be used during SSL BIND operations.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Novell Edirectory | <9.0.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9267 is a vulnerability in Novell eDirectory before version 9.0.3.1 that allows weaker ciphers to be used during SSL BIND operations.
CVE-2017-9267 has a severity rating of 7.5 (high).
Novell eDirectory versions up to 9.0.3.1 are affected by CVE-2017-9267.
To fix CVE-2017-9267, update Novell eDirectory to version 9.0.3.1 or later.
More information about CVE-2017-9267 can be found at the following link: [https://www.novell.com/support/kb/doc.php?id=7016794](https://www.novell.com/support/kb/doc.php?id=7016794)