First published: Thu Mar 13 2008(Updated: )
Richard Megginson discovered that Admin Server as used by Red Hat Directory Server 8 and Fedora Directory Server does not properly restrict access to CGI scripts. This could allow unauthenticated user to get access to information or perform tasks that should be restricted to authenticated administrative users.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Directory Server | ||
Red Hat 389 Directory Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-437320 has been classified as a security vulnerability that allows unauthorized access to restricted information.
To fix REDHAT-BUG-437320, ensure that proper access controls are implemented for CGI scripts in the Admin Server.
REDHAT-BUG-437320 affects Red Hat Directory Server 8 and Fedora Directory Server.
The risks of REDHAT-BUG-437320 include unauthorized access to sensitive information and the ability to perform administrative tasks by unauthenticated users.
A possible workaround for REDHAT-BUG-437320 is to temporarily restrict access to the Admin Server until a patch is applied.