CVE-2017-5186

HIGH

Novell iManager <2.7 SP7 Patch 9 - Info Disclosure

Title source: llm
STIX 2.1

Description

Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x before 8.8 SP8 Patch 9 Hotfix 2, and NetIQ eDirectory 9.x before 9.0.2 Hotfix 2 (9.0.2.2) use the deprecated MD5 hashing algorithm in a communications certificate.

References (7)

Core 7
Core References
Vendor Advisory x_refsource_confirm
https://www.novell.com/support/kb/doc.php?id=7016794
Vendor Advisory x_refsource_confirm
https://www.novell.com/support/kb/doc.php?id=3426981
Vendor Advisory x_refsource_confirm
https://www.novell.com/support/kb/doc.php?id=7016795
Issue Tracking x_refsource_confirm
https://bugzilla.novell.com/show_bug.cgi?id=1019789
Issue Tracking x_refsource_confirm
https://bugzilla.novell.com/show_bug.cgi?id=988749
Vendor Advisory x_refsource_confirm
https://www.novell.com/support/kb/doc.php?id=7010166
Issue Tracking x_refsource_confirm
https://bugzilla.novell.com/show_bug.cgi?id=1019041

Scores

CVSS v3 7.5
EPSS 0.0047
EPSS Percentile 64.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-327
Status published
Products (9)
n/a/NetIQ/Novell iManager and eDirectory NetIQ/Novell iManager and eDirectory
netiq/edirectory 9.0
netiq/edirectory 9.0.1
netiq/edirectory 9.0.2
netiq/imanager 3.0
netiq/imanager 3.0.1
netiq/imanager 3.0.2
novell/edirectory < 8.8
novell/imanager < 2.7
Published Apr 27, 2017
Tracked Since Feb 18, 2026