PT-2009-2191 · Apache+1 · Apache Tomcat+1
Publicado
2009-04-14
·
Atualizado
2009-04-29
·
CVE-2008-6722
CVSS v2.0
1.9
Baixa
| Vetor | AV:L/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Novell Access Manager version 3 SP4
Description:
The issue is related to the improper expiration of X.509 certificate sessions, allowing physically proximate attackers to obtain a logged-in session. This occurs when a victim's web-browser process continues to send the original and valid SSL sessionID. The problem is also related to the inability of Apache Tomcat to clear entries from its SSL cache.
Recommendations:
For Novell Access Manager version 3 SP4, consider restricting access to the SSL cache to minimize the risk of exploitation. As a temporary workaround, restrict the use of X.509 certificate sessions until a proper fix is available.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache Tomcat
Novell Access Manager