{ "id": "CVE-2017-5186", "sourceIdentifier": "meissner@suse.de", "published": "2017-04-27T14:59:00.263", "lastModified": "2019-10-03T00:03:26.223", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x before 8.8 SP8 Patch 9 Hotfix 2, and NetIQ eDirectory 9.x before 9.0.2 Hotfix 2 (9.0.2.2) use the deprecated MD5 hashing algorithm in a communications certificate." }, { "lang": "es", "value": "Novell iManager versi\u00f3n 2.7 anterior a SP7 Patch 9, Novell eDirectory 8.8.x anterior a 8.8 SP8 Patch 9 Hotfix 2, NetIQ eDirectory 9.x anterior a 9.0.2 Hotfix 2 (9.0.2.2) y NetIQ iManager 3.x anterior a 3.0.2.1 usan el algoritmo de hashing MD5 en un certificado para comunicaciones." } ], "metrics": { "cvssMetricV30": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH" }, "exploitabilityScore": 3.9, "impactScore": 3.6 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:P", "accessVector": "NETWORK", "accessComplexity": "MEDIUM", "authentication": "NONE", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 4.3 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.6, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-327" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:netiq:edirectory:9.0:*:*:*:*:*:*:*", "matchCriteriaId": "1822596B-5F37-4788-A596-32C994A4F39F" }, { "vulnerable": true, "criteria": "cpe:2.3:a:netiq:edirectory:9.0.1:*:*:*:*:*:*:*", "matchCriteriaId": "9D4F31E6-C304-43F0-997A-1DE23CD043CF" }, { "vulnerable": true, "criteria": "cpe:2.3:a:netiq:edirectory:9.0.2:*:*:*:*:*:*:*", "matchCriteriaId": "6B970239-2775-4377-AB77-6575F4EA6C4D" }, { "vulnerable": true, "criteria": "cpe:2.3:a:netiq:imanager:3.0:*:*:*:*:*:*:*", "matchCriteriaId": "5D3D7F7B-CF13-4729-BDC8-FA7C25EB0856" }, { "vulnerable": true, "criteria": "cpe:2.3:a:netiq:imanager:3.0.1:*:*:*:*:*:*:*", "matchCriteriaId": "8B44FED3-A5D0-4F0D-AD4F-329152057627" }, { "vulnerable": true, "criteria": "cpe:2.3:a:netiq:imanager:3.0.2:*:*:*:*:*:*:*", "matchCriteriaId": "8A555C67-FE51-414D-B93A-42DEC732EAAA" }, { "vulnerable": true, "criteria": "cpe:2.3:a:novell:edirectory:*:sp8_patch9:*:*:*:*:*:*", "versionEndIncluding": "8.8", "matchCriteriaId": "445EEDC7-BA29-44DF-88D6-205F16D3D68B" }, { "vulnerable": true, "criteria": "cpe:2.3:a:novell:imanager:*:sp7_patch8:*:*:*:*:*:*", "versionEndIncluding": "2.7", "matchCriteriaId": "9E43BD48-BFE5-49E4-AFD4-0B15A2FEA59A" } ] } ] } ], "references": [ { "url": "https://www.novell.com/support/kb/doc.php?id=3426981", "source": "meissner@suse.de", "tags": [ "Release Notes", "Vendor Advisory" ] }, { "url": "https://www.novell.com/support/kb/doc.php?id=7010166", "source": "meissner@suse.de", "tags": [ "Release Notes", "Vendor Advisory" ] }, { "url": "https://www.novell.com/support/kb/doc.php?id=7016794", "source": "meissner@suse.de", "tags": [ "Release Notes", "Vendor Advisory" ] }, { "url": "https://www.novell.com/support/kb/doc.php?id=7016795", "source": "meissner@suse.de", "tags": [ "Release Notes", "Vendor Advisory" ] } ] }