CVE-2017-9267

MEDIUM

Novell eDirectory <9.0.3.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

In Novell eDirectory before 9.0.3.1 the LDAP interface was not strictly enforcing cipher restrictions allowing weaker ciphers to be used during SSL BIND operations.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://www.novell.com/support/kb/doc.php?id=7016794

Scores

CVSS v3 6.5
EPSS 0.0071
EPSS Percentile 72.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-757
Status published
Products (1)
novell/edirectory < 9.0.3.1
Published Mar 02, 2018
Tracked Since Feb 18, 2026