Novell NetWare Management Portal Unrestricted Access

medium Nessus Plugin ID 10826

Synopsis

The remote web server discloses sensitive information.

Description

The NetWare Management Portal software is installed on this machine.
It allows anyone to view the current server configuration and locate other Portal servers on the network. It is possible to browse the server's filesystem by requesting the volume in the URL. However, a valid user account is needed to do so.

Solution

Disable this service if it is not in use or block connections to it.

Plugin Details

Severity: Medium

ID: 10826

File Name: DDI_Netware_Management_Portal.nasl

Version: 1.19

Type: remote

Family: Netware

Published: 12/12/2001

Updated: 6/12/2020

Configuration: Enable paranoid mode

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Information

Required KB Items: Settings/ParanoidReport