Vulnerability Name: | CCN-15991 | ||||||
Published: | 2004-04-27 | ||||||
Updated: | 2004-04-27 | ||||||
Summary: | Novell eDirectory for NetWare and Windows NT could allow an authenticated user to obtain elevated privileges on the system, caused by a vulnerability when Role Based Services (RBS) is used to assign privileges. RBS assigns eDirectory trustee assignments to the ROOT object, which could allow unauthorized users, that are added to Roles, to perform administrative tasks. | ||||||
CVSS v3 Severity: | 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H)
| ||||||
CVSS v2 Severity: | 9.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C)
| ||||||
Vulnerability Consequences: | Gain Privileges | ||||||
References: | Source: CCN Type: Novell Technical Information Document TID10092504 Role Based Services (RBS) rights to ROOT Source: CCN Type: BID-10223 Novell eDirectory Role Based Services Insecure Role Permissions Vulnerability Source: XF Type: UNKNOWN novell-edirectory-rbs-gain-privileges(15991) | ||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||
BACK |