Vulnerability Name: | CVE-2011-2223 (CCN-69061) | ||||||||
Assigned: | 2011-08-05 | ||||||||
Published: | 2011-08-05 | ||||||||
Updated: | 2015-10-29 | ||||||||
Summary: | The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 sends the Admin LDAP password in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-310 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2011-2223 Source: CCN Type: SA45527 Novell Data Synchronizer Mobility Pack Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory 45527 Source: CCN Type: Novell Document ID: 7009055 Password is exposed in UI and can be seen through a LAN Trace Source: CONFIRM Type: Vendor Advisory http://www.novell.com/support/viewContent.do?externalId=7009055 Source: CCN Type: OSVDB ID: 74521 Novell Data Synchronizer Mobility Pack Cleartext Admin LDAP Password Disclosure Source: BID Type: UNKNOWN 49069 Source: CCN Type: BID-49069 Novell Data Synchronizer Mobility Pack Multiple Remote Security Vulnerabilities Source: XF Type: UNKNOWN novell-data-ldap-info-disclosure(69061) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |