VYPR

Edirectory

by Microfocus

CVEs (20)

  • CVE-2017-7429HigMar 2, 2018
    risk 0.57cvss 8.8epss 0.01

    The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated attackers to execute JSP applets on the iManager server.

  • CVE-2021-22532HigSep 12, 2024
    risk 0.49cvss 7.6epss 0.00

    Possible NLDAP Denial of Service attack Vulnerability in eDirectory has been discovered in OpenText™ eDirectory before 9.2.4.0000.

  • CVE-2016-9166HigMar 21, 2019
    risk 0.49cvss 7.5epss 0.01

    NetIQ eDirectory versions prior to 9.0.2, under some circumstances, could be susceptible to downgrade of communication security.

  • CVE-2018-17950HigDec 12, 2018
    risk 0.49cvss 7.5epss 0.01

    Incorrect enforcement of authorization checks in eDirectory prior to 9.1 SP2

  • CVE-2018-7686HigAug 9, 2018
    risk 0.49cvss 7.5epss 0.01

    Information leakage vulnerability in NetIQ eDirectory before 9.1.1 HF1 due to shared memory usage.

  • CVE-2017-5186HigApr 27, 2017
    risk 0.49cvss 7.5epss 0.01

    Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x before 8.8 SP8 Patch 9 Hotfix 2, and NetIQ eDirectory 9.x before 9.0.2 Hotfix 2 (9.0.2.2) use the deprecated MD5 hashing algorithm in a communications certificate.

  • CVE-2021-38133HigSep 12, 2024
    risk 0.48cvss 7.4epss 0.00

    Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000.

  • CVE-2021-22533MedSep 12, 2024
    risk 0.42cvss 6.5epss 0.00

    Possible Insertion of Sensitive Information into Log File Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.4.0000.

  • CVE-2018-17952MedDec 12, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross site scripting vulnerability in eDirectory prior to 9.1 SP2

  • CVE-2018-7692MedAug 9, 2018
    risk 0.40cvss 6.1epss 0.01

    Unvalidated redirect vulnerability in in NetIQ eDirectory before 9.1.1 HF1.

  • CVE-2021-38131MedSep 12, 2024
    risk 0.35cvss 5.4epss 0.00

    Possible Cross-Site Scripting (XSS) Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.5.0000.

  • CVE-2021-22503MedSep 12, 2024
    risk 0.35cvss 5.4epss 0.00

    Possible Improper Neutralization of Input During Web Page Generation Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.3.0000.

  • CVE-2017-9285MedMar 2, 2018
    risk 0.35cvss 5.4epss 0.01

    NetIQ eDirectory before 9.0 SP4 did not enforce login restrictions when "ebaclient" was used, allowing unpermitted access to eDirectory services.

  • CVE-2021-38132MedSep 12, 2024
    risk 0.34cvss 5.3epss 0.00

    Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000.

  • CVE-2018-12461LowJul 10, 2018
    risk 0.23cvss 3.5epss 0.00

    Fixed issues with NetIQ eDirectory prior to 9.1.1 when checking certificate revocation.

  • CVE-2018-1346LowMar 21, 2018
    risk 0.20cvss 3.1epss 0.01

    Addresses denial of service attack to eDirectory versions prior to 9.1.

  • CVE-2012-0432Dec 25, 2012
    risk 0.08cvss epss 0.59

    Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote attackers to have an unspecified impact via unknown vectors.

  • CVE-2012-0430Dec 25, 2012
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 on Windows allows remote attackers to obtain an administrator cookie and bypass authorization checks via unknown vectors.

  • CVE-2012-0429Dec 25, 2012
    risk 0.00cvss epss 0.02

    dhost in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 on Windows allows remote authenticated users to cause a denial of service (daemon crash) via crafted characters in an HTTP request.

  • CVE-2012-0428Dec 25, 2012
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.