CVE-2014-0595: Novell Open Enterprise Server

Low severity, CVSS 2.6. EPSS: 0.3% chance of exploitation in the next 30 days.

/opt/novell/ncl/bin/nwrights in Novell Client for Linux in Novell Open Enterprise Server (OES) 11 Linux SP2 does not properly manage a certain array, which allows local users to obtain the S permission in opportunistic circumstances by leveraging the granting of the F permission by an administrator.

Affected products

  • Novell Open Enterprise Server: version 11.0 only

Published 2014-05-08. Last modified 2026-06-17.