{"api_version":"1","generated_at":"2026-07-23T09:04:50+00:00","cve":"CVE-2006-1628","urls":{"html":"https://cve.report/CVE-2006-1628","api":"https://cve.report/api/cve/CVE-2006-1628.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-1628","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-1628"},"summary":{"title":"CVE-2006-1628","description":"Adobe LiveCycle Workflow 7.01 and LiveCycle Forum Manager 7.01 allows users to authenticate and perform privileged actions when their account is marked \"OBSOLETE\" but the account is also active, within the authentication system.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-04-13 18:02:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.6","severity":"","vector":"AV:N/AC:H/Au:S/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:H/Au:S/C:P/I:P/A:P","baseScore":4.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://secunia.com/advisories/19620","name":"http://secunia.com/advisories/19620","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Secunia - Advisories - Adobe LiveCycle \"OBSOLETE\" User Information Disclosure","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.adobe.com/support/techdocs/333036.html","name":"http://www.adobe.com/support/techdocs/333036.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Security Advisory: LiveCycle information disclosure to OBSOLETE users - Support Knowledgebase","mime":"text/xml","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/17511","name":"http://www.securityfocus.com/bid/17511","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Adobe LiveCycle OBSOLETE User Access Validation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2006/1343","name":"http://www.vupen.com/english/advisories/2006/1343","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1015906","name":"http://securitytracker.com/id?1015906","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Adobe LiveCycle May Let OBSOLETE Users Continue to Access the System - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25779","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25779","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-1628","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-1628","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"1628","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"livecycle_form_manager","cpe6":"7.01","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"1628","cve":"CVE-2006-1628","epss":"0.020750000","percentile":"0.794810000","score_date":"2026-07-22","updated_at":"2026-07-23 00:09:35"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T17:19:49.256Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.adobe.com/support/techdocs/333036.html"},{"name":"1015906","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1015906"},{"name":"19620","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/19620"},{"name":"ADV-2006-1343","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/1343"},{"name":"adobe-livecycle-information-disclosure(25779)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25779"},{"name":"17511","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/17511"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-04-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"Adobe LiveCycle Workflow 7.01 and LiveCycle Forum Manager 7.01 allows users to authenticate and perform privileged actions when their account is marked \"OBSOLETE\" but the account is also active, within the authentication system."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-19T15:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.adobe.com/support/techdocs/333036.html"},{"name":"1015906","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1015906"},{"name":"19620","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/19620"},{"name":"ADV-2006-1343","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/1343"},{"name":"adobe-livecycle-information-disclosure(25779)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25779"},{"name":"17511","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/17511"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-1628","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Adobe LiveCycle Workflow 7.01 and LiveCycle Forum Manager 7.01 allows users to authenticate and perform privileged actions when their account is marked \"OBSOLETE\" but the account is also active, within the authentication system."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.adobe.com/support/techdocs/333036.html","refsource":"CONFIRM","url":"http://www.adobe.com/support/techdocs/333036.html"},{"name":"1015906","refsource":"SECTRACK","url":"http://securitytracker.com/id?1015906"},{"name":"19620","refsource":"SECUNIA","url":"http://secunia.com/advisories/19620"},{"name":"ADV-2006-1343","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/1343"},{"name":"adobe-livecycle-information-disclosure(25779)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25779"},{"name":"17511","refsource":"BID","url":"http://www.securityfocus.com/bid/17511"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-1628","datePublished":"2006-04-13T18:00:00.000Z","dateReserved":"2006-04-05T00:00:00.000Z","dateUpdated":"2024-08-07T17:19:49.256Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-04-13 18:02:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:S/C:P/I:P/A:P","baseScore":4.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:livecycle_form_manager:7.01:*:*:*:*:*:*:*","matchCriteriaId":"B663460F-45F2-4CF0-A13C-385D09D6EED3"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"1628","Ordinal":"1","Title":"CVE-2006-1628","CVE":"CVE-2006-1628","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"1628","Ordinal":"1","NoteData":"Adobe LiveCycle Workflow 7.01 and LiveCycle Forum Manager 7.01 allows users to authenticate and perform privileged actions when their account is marked \"OBSOLETE\" but the account is also active, within the authentication system.","Type":"Description","Title":"CVE-2006-1628"},{"CveYear":"2006","CveId":"1628","Ordinal":"2","NoteData":"2006-04-13","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"1628","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}