CVE-2004-2734

Novell NetWare 6.5 - Unauthenticated Access Control Bypass via Inconsistent Alias Tag Case

Title source: llm
STIX 2.1

Description

webadmin-apache.conf in Novell Web Manager of Novell NetWare 6.5 uses an uppercase Alias tag with an inconsistent lowercase directory tag for a volume, which allows remote attackers to bypass access control to the WEB-INF folder.

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/40478
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/9103
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/11000
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1011012
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/12049

Scores

EPSS 0.0156
EPSS Percentile 81.7%

Details

CWE
CWE-287
Status published
Products (1)
novell/netware 6.5 (4 CPE variants)
Published Dec 31, 2004
Tracked Since Feb 18, 2026