CVE Vulnerabilities

CVE-2017-7429

Improper Certificate Validation

Published: Mar 02, 2018 | Modified: Nov 07, 2023
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated attackers to execute JSP applets on the iManager server.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Edirectory Microfocus * 8.8.8 (including)
Edirectory Netiq 8.8.8-patch10 (including) 8.8.8-patch10 (including)
Edirectory Netiq 8.8.8-patch5 (including) 8.8.8-patch5 (including)
Edirectory Netiq 8.8.8-patch6 (including) 8.8.8-patch6 (including)
Edirectory Netiq 8.8.8-patch7 (including) 8.8.8-patch7 (including)
Edirectory Netiq 8.8.8-patch8 (including) 8.8.8-patch8 (including)
Edirectory Netiq 8.8.8-patch9 (including) 8.8.8-patch9 (including)

Potential Mitigations

References