First published: Fri Mar 02 2018(Updated: )
NetIQ eDirectory before 9.0 SP4 did not enforce login restrictions when "ebaclient" was used, allowing unpermitted access to eDirectory services.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Microfocus eDirectory | <=9.0 | |
Micro Focus NetIQ eDirectory | =9.0-sp1 | |
Micro Focus NetIQ eDirectory | =9.0-sp2 | |
Micro Focus NetIQ eDirectory | =9.0-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9285 is considered a medium severity vulnerability due to the potential for unauthorized access to eDirectory services.
To fix CVE-2017-9285, you should upgrade to NetIQ eDirectory version 9.0 SP4 or later.
CVE-2017-9285 affects NetIQ eDirectory versions prior to 9.0 SP4, including versions 9.0, 9.0 SP1, 9.0 SP2, and 9.0 SP3.
The consequences of CVE-2017-9285 include unauthorized access to eDirectory services due to insufficient login restrictions.
As of the last reports, there is no indication that CVE-2017-9285 is being actively exploited in the wild.