First published: Fri Mar 02 2018(Updated: )
The LDAP backend in Novell eDirectory before 9.0 SP4 when switched to EBA (Enhanced Background Authentication) kept open connections without EBA.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Novell Edirectory | <=9.0 | |
Novell Edirectory | =9.0-sp1 | |
Novell Edirectory | =9.0-sp2 | |
Novell Edirectory | =9.0-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9277 is a vulnerability in Novell eDirectory before 9.0 SP4 that allows for open connections without Enhanced Background Authentication (EBA).
The severity of CVE-2017-9277 is high with a CVSS score of 7.5.
CVE-2017-9277 affects Novell eDirectory versions before 9.0 SP4 when switched to EBA by keeping open connections without EBA.
Novell eDirectory versions 9.0, 9.0-sp1, 9.0-sp2, and 9.0-sp3 are affected by CVE-2017-9277.
To fix CVE-2017-9277, update Novell eDirectory to version 9.0 SP4 or later.