vendor:
eDirectory
by:
karak0rsan, Hellcode Research
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: eDirectory
Affected Version From: 8.8 SP5
Affected Version To: 8.8 SP5
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Novell eDirectory 8.8 SP5 Denial of Service Vulnerability
Novell eDirectory 8.8 SP5 is vulnerable to a denial of service attack. If a remote attacker sends Unicode strings with Http Request to '8028 port' ('8028' is the default port of Novell eDirectory Dhost Http Server), the attacker can cause the system to consume %100 of the CPU resources.
Mitigation:
Ensure that the Novell eDirectory 8.8 SP5 is updated to the latest version and that the port 8028 is not exposed to the public internet.