INFORMATION

Name : CVE-2008-5696 First Publication : 2008-12-19
Severity : Critical Last Modification : 2009-08-12

SCORING CVSS v2

Cvss Base Score : 9.3 Attack Range : Network
Cvss Impact Score : 10 Attack Complexity : Medium
Cvss Expoit Score : 8.6 Authentification : None Required

Calculate full CVSS 2.0 Vectors scores

DETAIL

Novell NetWare 6.5 before Support Pack 8, when an OES2 Linux server is installed into the NDS tree, does not require a password for the ApacheAdmin console, which allows remote attackers to reconfigure the Apache HTTP Server via console operations.



CWE COMMON WEAKNESS ENUMERATION

Weakness : CWE-255 - Credentials Management (From NVD)
CPE COMMON PLATFORM ENUMERATION (from NVD)

OPEN SOURCE VULNERABILTY DATABASE (OSVDB)

50475 : Novell NetWare ApacheAdmin Console Unauthenticated Access.


SECONDARY(S) SOURCE(S)