Vulnerabilities > Netiq > Edirectory

DATE CVE VULNERABILITY TITLE RISK
2018-07-10 CVE-2018-12461 Improper Certificate Validation vulnerability in Netiq Edirectory 9.1.1
Fixed issues with NetIQ eDirectory prior to 9.1.1 when checking certificate revocation.
network
low complexity
netiq CWE-295
7.5
2018-03-21 CVE-2018-1346 Unspecified vulnerability in Netiq Edirectory
Addresses denial of service attack to eDirectory versions prior to 9.1.
network
low complexity
netiq
7.5
2018-03-02 CVE-2017-9285 Improper Authentication vulnerability in multiple products
NetIQ eDirectory before 9.0 SP4 did not enforce login restrictions when "ebaclient" was used, allowing unpermitted access to eDirectory services.
network
low complexity
netiq microfocus CWE-287
critical
9.8
2018-03-02 CVE-2017-7429 Improper Certificate Validation vulnerability in multiple products
The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated attackers to execute JSP applets on the iManager server.
network
low complexity
netiq microfocus CWE-295
8.8
2017-04-27 CVE-2017-5186 Use of a Broken or Risky Cryptographic Algorithm vulnerability in multiple products
Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x before 8.8 SP8 Patch 9 Hotfix 2, and NetIQ eDirectory 9.x before 9.0.2 Hotfix 2 (9.0.2.2) use the deprecated MD5 hashing algorithm in a communications certificate.
network
low complexity
netiq novell CWE-327
7.5