Novell NetWare LDAP Server Anonymous Bind

medium Nessus Plugin ID 12104

Language:

Synopsis

Information can be read on the remote LDAP server.

Description

The server's directory base is set to NULL. This allows information to be enumerated without any prior knowledge of the directory structure.

Solution

Disable or restrict anonymous binds in LDAP if not required.

See Also

http://www.nessus.org/u?569899d0

Plugin Details

Severity: Medium

ID: 12104

File Name: netware_ldap_search_request.nasl

Version: 1.14

Type: remote

Family: Netware

Published: 3/15/2004

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Information

CPE: cpe:/o:novell:netware