Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 =========================================================================== AUSCERT Security Bulletin ASB-2014.0074 A number of vulnerabilities have been identified in Novell iManager prior to version 2.7 SP7 Patch 1 Hotfix 1. 8 July 2014 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: Novell iManager Operating System: SUSE Netware Red Hat Windows Impact/Access: Denial of Service -- Remote/Unauthenticated Access Confidential Data -- Remote with User Interaction Resolution: Patch/Upgrade CVE Names: CVE-2014-0096 CVE-2014-0075 Member content until: Thursday, August 7 2014 Reference: ESB-2014.1092 ESB-2014.1082 ESB-2014.1073 ESB-2014.0828 OVERVIEW A number of vulnerabilities have been identified in Novell iManager prior to version 2.7 SP7 Patch 1 Hotfix 1. [1] IMPACT The vendor has provided the following details regarding these issues: "Issues resolved in iManager 2.7 SP7 Patch 1 Hotfix 1 July 2014 NTLS 2.0.6.1 - Tomcat security vulnerabilities (CVE-2014-0075 and CVE-2014-0096) (Bug 881886)" [1] MITIGATION It is recommended that administrators update Novell iManager to correct these issues. REFERENCES [1] History of Issues Resolved for Novell iManager 2.7 http://www.novell.com/support/kb/doc.php?id=7010166 AusCERT has made every effort to ensure that the information contained in this document is accurate. However, the decision to use the information described is the responsibility of each user or organisation. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBU7uAYRLndAQH1ShLAQIHvg//f8FOa6RwBDeuycI1OC5Ln+6dvnE+t/mo hmNFY5lbSUfti8TSvSjRCzolX1eL0GDdV/T2Us+5K9ipndF2nNuxiONNYymdeOec MmQr2Q4mXh4loeH1l7tTwDzaVmXA6DQ+CwedF00b7+uxD5pUMPswdaIR+J9B3f0I +BtAl8B+ywaCqOQUbxmLp7Rv1RkbZU9cnoLQ5e8Nl1JYK6ohUU/UTHS3prxAneAd OlO9QAWws9ZHgrEP1ugm9ogiNx+F25MSCwV/b3O+Itih7llp/daCaat+FYEPqPiy Yl9kVt+zkmLK5cQtA2bSpvOr3SeMxr+3osAD6fViMz+X4WNwhGtSyJPhymte3mBd pkNFIy71OXaxhkyd2y5klJZb+CvWJBFliDLHfIwmxJ8PpowNnjoNPGc1nqJSLD9v apyR0ZtcBMOpsm870ycYr30e9UcYHH5UOTT3lPb1+1mQSJ42EIMDN71xaCqrS1wY /vELOUxHWklws7JkzwEpQfi4JKDo8XFOKdXP961kf+WZjoQ5paUPSplNbCc9HHr8 zGnrFEA93YyQEAquRNyo67OUCBuhzWvuHnb6nset72m7KhphHF/XCdktgpM/pC2q zuo1uywNBFdQGy5+cUt6oeCA8Ke9NqMyC/6397KAidcIgEzoXvwK5g92ohn1kiNj R9+Ke0RyMA0= =kblg -----END PGP SIGNATURE-----