If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

 
Go Back  dBforums > Database Server Software > DB2 > DB2 posr migration Vulnerabilities ... need solution to fix it

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 04-30-10, 08:29
sandesh_dbforum sandesh_dbforum is offline
Registered User
 
Join Date: Apr 2010
Posts: 4
DB2 posr migration Vulnerabilities ... need solution to fix it

Hi Friends,

Can you please check the below points and help me in closing these observations which were raised post migration of DB2 version 8.2.8 to 8.2.18:

1) Vulnerability: LDAP NULL BASE Search Access
Description: The remote LDAP server may disclose sensitive information.
Recommendation: If the remote LDAP server supports a version of the LDAP protocol before v3, consider whether to disable NULL BASE queries on your LDAP server.

2) Vulnerability: LDAP Server NULL Bind Connection Information Disclosure
Description: The remote LDAP server allows anonymous access.
Recommendation: Unless the remote LDAP server supports LDAP v3, configure it to disallow NULL BINDs.

Please help to fix these issues.


Regards,
Sandesh
Reply With Quote
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On