Edirectory
Vendor:
First CVE: Dec 25, 2012 · Active for 13 years
16
Total CVEs
More Total CVEs than 92% of tracked products
5.3
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Edirectory over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 25, 2012
13 years ago
Most Recent CVE
Sep 12, 2024
681 days ago
CVE Severity & Scoring
Edirectory16 CVEs
50%
31%
19%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (75.0%)
Unknown4 (25.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (75.0%)
High0 (0.0%)
Unknown4 (25.0%)
User Interaction
None7 (43.8%)
Unknown4 (25.0%)
Required5 (31.3%)
Privileges Required
Low1 (6.3%)
High0 (0.0%)
None11 (68.8%)
Unknown4 (25.0%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-0432HIGH Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote attackers to have an unspecified impact via unknown vectors. | Dec 25, 2012 | 10.0 | 81 | NO | YES |
CVE-2017-9285CRITICAL NetIQ eDirectory before 9.0 SP4 did not enforce login restrictions when "ebaclient" was used, allowing unpermitted access to eDirectory services. | Mar 2, 2018 | 9.8 | 30 | NO | NO |
CVE-2017-7429HIGH The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated attackers to execute JS | Mar 2, 2018 | 8.8 | 27 | NO | NO |
CVE-2021-38132CRITICAL Possible
External Service Interaction attack
in eDirectory has been discovered in
OpenText™ eDirectory. This impact all version before 9.2.6.0000. | Sep 12, 2024 | 9.8 | 25 | NO | NO |
CVE-2018-7686HIGH Information leakage vulnerability in NetIQ eDirectory before 9.1.1 HF1 due to shared memory usage. | Aug 9, 2018 | 7.5 | 25 | NO | NO |
CVE-2021-22533CRITICAL Possible Insertion of Sensitive Information into Log File Vulnerability
in eDirectory has been discovered in
OpenText™ eDirectory 9.2.4.0000. | Sep 12, 2024 | 9.1 | 24 | NO | NO |
CVE-2018-17950HIGH Incorrect enforcement of authorization checks in eDirectory prior to 9.1 SP2 | Dec 12, 2018 | 7.5 | 23 | NO | NO |
CVE-2021-22532HIGH Possible NLDAP Denial of Service attack Vulnerability
in eDirectory has been discovered in
OpenText™
eDirectory before 9.2.4.0000. | Sep 12, 2024 | 7.5 | 22 | NO | NO |
CVE-2018-17952MEDIUM Cross site scripting vulnerability in eDirectory prior to 9.1 SP2 | Dec 12, 2018 | 6.1 | 21 | NO | NO |
CVE-2018-7692MEDIUM Unvalidated redirect vulnerability in in NetIQ eDirectory before 9.1.1 HF1. | Aug 9, 2018 | 6.1 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
6.2% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
6.2% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CNAs Publishing CVEs For Edirectory
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.1 | 1 | 7.5 | 0.8% | 0 | 0 |
| 8.8.7.1 | 4 | 6.2 | 16.1% | 0 | 1 |
| 8.8.7.0 | 4 | 6.2 | 16.1% | 0 | 1 |
| 8.8.6.6 | 3 | 4.9 | 2.0% | 0 | 0 |
| 8.8.6.5 | 3 | 4.9 | 2.0% | 0 | 0 |
| 8.8.6.4 | 3 | 4.9 | 2.0% | 0 | 0 |
| 8.8.6.3 | 3 | 4.9 | 2.0% | 0 | 0 |
| 8.8.6.2 | 3 | 4.9 | 2.0% | 0 | 0 |
| 8.8.6.1 | 3 | 4.9 | 2.0% | 0 | 0 |
| 8.8.6.0 | 3 | 4.9 | 2.0% | 0 | 0 |