search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Novell NetWare default installation contains sample files that disclose sensitive server information

Vulnerability Note VU#159203

Original Release Date: 2002-06-11 | Last Revised: 2003-04-03

Overview

Novell NetWare 5.1 is a network management operating system that enables access to files, printers, directories, email, databases, and other network interfaces, as well as providing a web interface. There is an insecure default configuration that places several sample applications in the webroot. Remote users may be able to use these applications to gain sensitive information about the server's configuration, and passwords.

Description

There are several sample applications that ship with Novell NetWare 5.1 and are installed in the webroot by default. If these applications are left in the webroot of a production machine, remote users may be able to gain sensitive information about the server's configuration, including passwords.

Impact

Remote users may be able to use these applications to gain sensitive information about the server's configuration, including passwords.

Solution

Please see http://support.novell.com/cgi-bin/search/searchtid.cgi?/10064452.htm.

Remove sample applications prior to placing the server into production.

Vendor Information

159203
 

Novell Affected

Notified:  May 16, 2002 Updated: September 19, 2002

Status

Affected

Vendor Statement

Fixes will be made available in CSP8, NetWare 5.1 Support Pack 5, NetWare 6 Support Pack 2, slated in August 2002.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.

If you have feedback, comments, or additional information about this vulnerability, please send us email.


CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

Thanks to ProCheckUp for reporting this vulnerability.

This document was written by Jason A Rafail.

Other Information

CVE IDs: None
Severity Metric: 7.50
Date Public: 2002-05-29
Date First Published: 2002-06-11
Date Last Updated: 2003-04-03 17:48 UTC
Document Revision: 14

Sponsored by CISA.