Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux
EMC Isilon OneFS LDAP Injection Vulnerability
Information
Severity
Severity
High
Family
Family
General
CVSSv2 Base
CVSSv2 Base
7.2
CVSSv2 Vector
CVSSv2 Vector
AV:L/AC:L/Au:N/C:C/I:C/A:C
Solution Type
Solution Type
Vendor Patch
Created
Created
7 years ago
Modified
Modified
5 years ago
Summary
EMC Isilon OneFS is affected by an LDAP injection vulnerability that could potentially be exploited by a malicious user to compromise the system.
Insight
Insight
A malicious high-privileged local user may leverage the LDAP injection vulnerability by injecting an asterisk into a username in LDAP searches, which may enable the attacker to impersonate other users on the system.
Affected Software
Affected Software
EMC Isilon OneFS 7.1.0.x, 7.1.1.0 - 7.1.1.10, 7.2.0.x, 7.2.1.0 - 7.2.1.2 and 8.0.0.0.
Detection Method
Detection Method
Checks if a vulnerable version is present on the target host.
Solution
Solution
Update 7.1.1.11, 7.2.1.3, 8.0.0.1 or later versions.