Novell NetWare LDAP Server Anonymous Bind

Medium Nessus Plugin ID 12104

Synopsis

Information can be read on the remote LDAP server.

Description

The server's directory base is set to NULL. This allows information to be enumerated without any prior knowledge of the directory structure.

Solution

Disable or restrict anonymous binds in LDAP if not required.

See Also

http://www.nessus.org/u?569899d0

Plugin Details

Severity: Medium

ID: 12104

File Name: netware_ldap_search_request.nasl

Version: Revision: 1.13

Type: remote

Family: Netware

Published: 2004/03/15

Modified: 2013/01/25

Dependencies: 20870

Risk Information

Risk Factor: Medium

CVSS v2.0

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Information

CPE: cpe:/o:novell:netware