← back
CVE-2017-9285mediumCWE-284

Login restrictions not applied when using ebaclient against NetIQ eDirectory EBA interface

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.4epss 1.2%
exploitation probability
1.2%top 34% of all CVEs
observed exploitation
nono source reports it
NetIQ eDirectory before 9.0 SP4 did not enforce login restrictions when "ebaclient" was used, allowing unpermitted access to eDirectory services.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Affected products
NetIQ · eDirectory