A security vulnerability in cookie handling in the http stack implementation in NDSD in Novell eDirectory before 9.0.1 allows remote attackers to bypass intended access restrictions by leveraging predictable cookies.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NNovell Edirectory
APPNovell≤ 9.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2008-5038CRITICAL9.8PL ✓same product
Use-after-free w Novell eDirectory — RCE przez protokół NCP
CVE-2002-2119CRITICAL9.8PL ✓same product
Novell eDirectory — brak rozróżniania wielkości liter w hasłach
CVE-2017-5186HIGH7.5same product
Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x before 8.8 ...
CVE-2016-9167HIGH7.5same product
NDSD in Novell eDirectory before 9.0.2 did not calculate ACLs on LDAP objects across partition boundaries corr...
CVE-2009-4653HIGH9.0same product
Stack-based buffer overflow in the dhost module in Novell eDirectory 8.8 SP5 for Windows allows remote authent...