Edirectory

Vendor:

First CVE: Dec 25, 2012 · Active for 13 years

16
Total CVEs
More Total CVEs than 92% of tracked products
5.3
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Edirectory over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 25, 2012
13 years ago
Most Recent CVE
Sep 12, 2024
681 days ago

CVE Severity & Scoring

Edirectory16 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (75.0%)
Unknown4 (25.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (75.0%)
High0 (0.0%)
Unknown4 (25.0%)
User Interaction
None7 (43.8%)
Unknown4 (25.0%)
Required5 (31.3%)
Privileges Required
Low1 (6.3%)
High0 (0.0%)
None11 (68.8%)
Unknown4 (25.0%)

Top CVEs

Signals from CVEs in this product scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote attackers to have an unspecified impact via unknown vectors.
Dec 25, 201210.081NOYES
NetIQ eDirectory before 9.0 SP4 did not enforce login restrictions when "ebaclient" was used, allowing unpermitted access to eDirectory services.
Mar 2, 20189.830NONO
The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated attackers to execute JS
Mar 2, 20188.827NONO
Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000.
Sep 12, 20249.825NONO
Information leakage vulnerability in NetIQ eDirectory before 9.1.1 HF1 due to shared memory usage.
Aug 9, 20187.525NONO
Possible Insertion of Sensitive Information into Log File Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.4.0000.
Sep 12, 20249.124NONO
Incorrect enforcement of authorization checks in eDirectory prior to 9.1 SP2
Dec 12, 20187.523NONO
Possible NLDAP Denial of Service attack Vulnerability in eDirectory has been discovered in OpenText™ eDirectory before 9.2.4.0000.
Sep 12, 20247.522NONO
Cross site scripting vulnerability in eDirectory prior to 9.1 SP2
Dec 12, 20186.121NONO
Unvalidated redirect vulnerability in in NetIQ eDirectory before 9.1.1 HF1.
Aug 9, 20186.121NONO

Exploit Exposure

Signals from CVEs in this product scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
6.2% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
6.2% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (16 CVEs).

Media Mentions

Signals from CVEs in this product scope (16 CVEs).

Top CNAs Publishing CVEs For Edirectory

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.117.50.8%00
8.8.7.146.216.1%01
8.8.7.046.216.1%01
8.8.6.634.92.0%00
8.8.6.534.92.0%00
8.8.6.434.92.0%00
8.8.6.334.92.0%00
8.8.6.234.92.0%00
8.8.6.134.92.0%00
8.8.6.034.92.0%00