1.9
CVSSv2

CVE-2008-6722

Published: 14/04/2009 Updated: 29/04/2009
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Novell Access Manager 3 SP4 does not properly expire X.509 certificate sessions, which allows physically proximate malicious users to obtain a logged-in session by using a victim's web-browser process that continues to send the original and valid SSL sessionID, related to inability of Apache Tomcat to clear entries from its SSL cache.

Vulnerable Product Search on Vulmon Subscribe to Product

novell access manager 3