ID

VAR-201002-0039


CVE

CVE-2009-4655


TITLE

Novell eDirectory of dhost Web Session hijacking vulnerability in services

Trust: 0.8

sources: JVNDB: JVNDB-2009-005277

DESCRIPTION

The dhost web service in Novell eDirectory 8.8.5 uses a predictable session cookie, which makes it easier for remote attackers to hijack sessions via a modified cookie. Novell eDirectory is a cross-platform directory server. Novell eDirectory is prone to a session-hijacking vulnerability. An attacker can exploit this issue to gain access to the affected application. Novell eDirectory 8.8.5 is vulnerable; other versions may also be affected

Trust: 2.43

sources: NVD: CVE-2009-4655 // JVNDB: JVNDB-2009-005277 // CNVD: CNVD-2010-0380 // BID: 38782

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2010-0380

AFFECTED PRODUCTS

vendor:novellmodel:edirectoryscope:eqversion:8.8.5

Trust: 2.7

vendor:nomodel: - scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2010-0380 // BID: 38782 // JVNDB: JVNDB-2009-005277 // CNNVD: CNNVD-201002-281 // NVD: CVE-2009-4655

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2009-4655
value: HIGH

Trust: 1.0

NVD: CVE-2009-4655
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201002-281
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2009-4655
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

sources: JVNDB: JVNDB-2009-005277 // CNNVD: CNNVD-201002-281 // NVD: CVE-2009-4655

PROBLEMTYPE DATA

problemtype:CWE-310

Trust: 1.8

sources: JVNDB: JVNDB-2009-005277 // NVD: CVE-2009-4655

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201002-281

TYPE

encryption problem

Trust: 0.6

sources: CNNVD: CNNVD-201002-281

CONFIGURATIONS

sources: JVNDB: JVNDB-2009-005277

PATCH

title:3426981url:http://www.novell.com/support/kb/doc.php?id=3426981

Trust: 0.8

sources: JVNDB: JVNDB-2009-005277

EXTERNAL IDS

db:NVDid:CVE-2009-4655

Trust: 3.3

db:OSVDBid:60035

Trust: 1.6

db:JVNDBid:JVNDB-2009-005277

Trust: 0.8

db:CNVDid:CNVD-2010-0380

Trust: 0.6

db:CNNVDid:CNNVD-201002-281

Trust: 0.6

db:BIDid:38782

Trust: 0.3

sources: CNVD: CNVD-2010-0380 // BID: 38782 // JVNDB: JVNDB-2009-005277 // CNNVD: CNNVD-201002-281 // NVD: CVE-2009-4655

REFERENCES

url:http://www.metasploit.com/modules/auxiliary/admin/edirectory/edirectory_dhost_cookie

Trust: 1.9

url:http://www.metasploit.com/redmine/projects/framework/repository/entry/modules/auxiliary/admin/edirectory/edirectory_dhost_cookie.rb

Trust: 1.6

url:http://osvdb.org/60035

Trust: 1.6

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/56613

Trust: 1.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2009-4655

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2009-4655

Trust: 0.8

url:http://www.novell.com/products/edirectory/

Trust: 0.3

sources: BID: 38782 // JVNDB: JVNDB-2009-005277 // CNNVD: CNNVD-201002-281 // NVD: CVE-2009-4655

CREDITS

The issue was reported in a Metasploit module.

Trust: 0.3

sources: BID: 38782

SOURCES

db:CNVDid:CNVD-2010-0380
db:BIDid:38782
db:JVNDBid:JVNDB-2009-005277
db:CNNVDid:CNNVD-201002-281
db:NVDid:CVE-2009-4655

LAST UPDATE DATE

2024-11-23T22:09:13.404000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2010-0380date:2010-03-17T00:00:00
db:BIDid:38782date:2010-03-14T00:00:00
db:JVNDBid:JVNDB-2009-005277date:2012-09-25T00:00:00
db:CNNVDid:CNNVD-201002-281date:2010-03-01T00:00:00
db:NVDid:CVE-2009-4655date:2024-11-21T01:10:08.960

SOURCES RELEASE DATE

db:CNVDid:CNVD-2010-0380date:2010-03-17T00:00:00
db:BIDid:38782date:2010-03-14T00:00:00
db:JVNDBid:JVNDB-2009-005277date:2012-09-25T00:00:00
db:CNNVDid:CNNVD-201002-281date:2010-02-26T00:00:00
db:NVDid:CVE-2009-4655date:2010-02-26T18:30:00.447