Remote Authentication Flaw in iPlanet Web Server and Netscape Enterprise Server
CVE-2002-1654
Currently unrated
What is CVE-2002-1654?
A significant security weakness in iPlanet Web Server Enterprise Edition and Netscape Enterprise Server versions 4.0 and 4.1 allows remote attackers to leverage the wp-force-auth command for HTTP Basic Authentication. This vulnerability facilitates an avenue for attackers to perform brute force password guessing attacks, potentially compromising user credentials without immediate detection. Implementing effective security measures is critical to mitigate this risk.