First published: Wed Dec 12 2018(Updated: )
Incorrect enforcement of authorization checks in eDirectory prior to 9.1 SP2
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Microfocus eDirectory | <=9.1 | |
Microfocus eDirectory | =9.1-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17950 has been rated as a medium severity vulnerability due to improper enforcement of authorization checks.
To mitigate CVE-2018-17950, users should upgrade to eDirectory version 9.1 SP2 or later.
CVE-2018-17950 affects Micro Focus eDirectory versions prior to 9.1 SP2, including versions up to 9.1 and 9.1 SP1.
CVE-2018-17950 impacts the security and authorization processes within eDirectory, potentially allowing unauthorized access.
Yes, CVE-2018-17950 can be exploited remotely if the affected eDirectory system is accessible over a network.