CVE-2008-5696
Severity CVSS v4.0:
Pending analysis
Type:
CWE-255
Credentials Management
Publication date:
19/12/2008
Last modified:
09/04/2025
Description
Novell NetWare 6.5 before Support Pack 8, when an OES2 Linux server is installed into the NDS tree, does not require a password for the ApacheAdmin console, which allows remote attackers to reconfigure the Apache HTTP Server via console operations.
Impact
Base Score 2.0
9.30
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:novell:netware:*:sp7:*:*:*:*:*:* | 6.5 (including) | |
| cpe:2.3:o:novell:netware:6.5:*:*:*:*:*:*:* | ||
| cpe:2.3:o:novell:netware:6.5:sp1:*:*:*:*:*:* | ||
| cpe:2.3:o:novell:netware:6.5:sp1.1a:*:*:*:*:*:* | ||
| cpe:2.3:o:novell:netware:6.5:sp1.1b:*:*:*:*:*:* | ||
| cpe:2.3:o:novell:netware:6.5:sp2:*:*:*:*:*:* | ||
| cpe:2.3:o:novell:netware:6.5:sp3:*:*:*:*:*:* | ||
| cpe:2.3:o:novell:netware:6.5:sp4:*:*:*:*:*:* | ||
| cpe:2.3:o:novell:netware:6.5:sp5:*:*:*:*:*:* | ||
| cpe:2.3:o:novell:netware:6.5:sp6:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://secunia.com/advisories/32989
- http://www.novell.com/support/viewContent.do?externalId=7001907
- http://www.securityfocus.com/bid/32657
- http://www.securitytracker.com/id?1021350=
- http://www.vupen.com/english/advisories/2008/3368
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47104
- http://secunia.com/advisories/32989
- http://www.novell.com/support/viewContent.do?externalId=7001907
- http://www.securityfocus.com/bid/32657
- http://www.securitytracker.com/id?1021350=
- http://www.vupen.com/english/advisories/2008/3368
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47104



