CVE-2016-9168: Novell Edirectory

Medium severity, CVSS 6.5. EPSS: 1.5% chance of exploitation in the next 30 days.

A missing X-Frame-Options header in the NDS Utility Monitor in NDSD in Novell eDirectory before 9.0.2 could be used by remote attackers for clickjacking.

Affected products

  • Novell Edirectory: up to and including 9.0.1

Published 2017-03-23. Last modified 2026-06-17.