CVE-2016-9167

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
23/03/2017
Last modified:
20/04/2025

Description

NDSD in Novell eDirectory before 9.0.2 did not calculate ACLs on LDAP objects across partition boundaries correctly, which could lead to a privilege escalation by modifying user attributes that would otherwise be filtered by an ACL.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:novell:edirectory:*:hotfix2:*:*:*:*:*:* 9.0.1 (including)