vendor:
Novell eDirectory
by:
hdm
5.5
CVSS
MEDIUM
Session-Hijacking
CWE
Product Name: Novell eDirectory
Affected Version From: Novell eDirectory 8.8.5
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2009
Novell eDirectory DHOST Predictable Session Cookie
This module is able to predict the next session cookie value issued by the DHOST web service of Novell eDirectory 8.8.5. An attacker can run this module, wait until the real administrator logs in, then specify the predicted cookie value to hijack their session.
Mitigation:
Apply the appropriate patch provided by Novell to fix the vulnerability. Disable the DHOST web service if not in use.