CVE-2002-1654
iPlanet Web Server Enterprise Edition and Netscape Enterprise Server 4.0 and 4.1 allows remote attackers to conduct HTTP Basic Authentication via the wp-force-auth Web Publisher command, which provides a distinct attack vector and may make it easier to…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.62%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
iPlanet Web Server Enterprise Edition and Netscape Enterprise Server 4.0 and 4.1 allows remote attackers to conduct HTTP Basic Authentication via the wp-force-auth Web Publisher command, which provides a distinct attack vector and may make it easier to conduct brute force password guessing without detection.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.62% probability · 85th percentile
- CISA KEV
- Not listed
- Affected
- iplanet/iplanet web server · netscape/enterprise server
- Source
- cve@mitre.org
References
- http://lists.virus.org/vulnwatch-0201/msg00008.htmlExploit, Patch
- http://securitytracker.com/id?1003157Exploit, Patch
- http://www.kb.cert.org/vuls/id/985347Patch, US Government Resource
- http://www.kb.cert.org/vuls/id/AAMN-567NFX
- http://www.procheckup.com/vulnerabilities/pr0105.html
- http://www.securiteam.com/securitynews/5IP0G0060Q.htmlExploit, Patch
- http://www.securityfocus.com/bid/3831Exploit, Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7845
- http://lists.virus.org/vulnwatch-0201/msg00008.htmlExploit, Patch
- http://securitytracker.com/id?1003157Exploit, Patch
- http://www.kb.cert.org/vuls/id/985347Patch, US Government Resource
- http://www.kb.cert.org/vuls/id/AAMN-567NFX
- http://www.procheckup.com/vulnerabilities/pr0105.html
- http://www.securiteam.com/securitynews/5IP0G0060Q.htmlExploit, Patch
- http://www.securityfocus.com/bid/3831Exploit, Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7845
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.