CVE-2017-9267: eDirectory LDAP peer certificate validation issue
Published Mar 2, 2018
·Updated
In Novell eDirectory before 9.0.3.1 the LDAP interface was not strictly enforcing cipher restrictions allowing weaker ciphers to be used during SSL BIND operations.
Affected Software
1 affected component
Novell eDirectory<9.0.3.1
Event History
Mar 2, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2017-9267?
CVE-2017-9267 is a vulnerability in Novell eDirectory before version 9.0.3.1 that allows weaker ciphers to be used during SSL BIND operations.
2
How severe is CVE-2017-9267?
CVE-2017-9267 has a severity rating of 7.5 (high).
3
What software is affected by CVE-2017-9267?
Novell eDirectory versions up to 9.0.3.1 are affected by CVE-2017-9267.
4
How can I fix CVE-2017-9267?
To fix CVE-2017-9267, update Novell eDirectory to version 9.0.3.1 or later.
5
Where can I find more information about CVE-2017-9267?
More information about CVE-2017-9267 can be found at the following link: [https://www.novell.com/support/kb/doc.php?id=7016794](https://www.novell.com/support/kb/doc.php?id=7016794)