VULNERABILITY INTELLIGENCE

CVE-2016-9167

CVSS score7.5 HIGH
EPSS probability1.24%
CISA KEVNot currently listed
Published2017-03-23
Last modified2026-06-17
CVSS vectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Description

NDSD in Novell eDirectory before 9.0.2 did not calculate ACLs on LDAP objects across partition boundaries correctly, which could lead to a privilege escalation by modifying user attributes that would otherwise be filtered by an ACL.

Primary references