The Identity Server in Novell Access Manager before 3.1 SP1 allows attackers with disabled Active Directory accounts to authenticate using X.509 authentication, which bypasses intended access restrictions.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2009-4842 | The Identity Server in Novell Access Manager before 3.1 SP1 allows attackers with disabled Active Directory accounts to authenticate using X.509 authentication, which bypasses intended access restrictions. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T16:18:39.843Z
Reserved: 2010-05-26T00:00:00.000Z
Link: CVE-2009-4879
No data.
Status : Deferred
Published: 2010-05-26T18:30:01.767
Modified: 2025-04-11T00:51:21.963
Link: CVE-2009-4879
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD