SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2008-0926

The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on client-side authentication, which allows remote attackers to bypass authentication via requests for /SOAP URIs, and cause a denial of…

HIGH 7.5EPSS 58.2%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 58.2%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on client-side authentication, which allows remote attackers to bypass authentication via requests for /SOAP URIs, and cause a denial of service (daemon shutdown) or read arbitrary files. NOTE: it was later reported that 8.7.3.10 (aka 8.7.3 SP10) is also affected.

CVSS 2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
58.18% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
novell/edirectory
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.