Novell Access Manager Local Browser Security Bypass Vulnerability
BID:32121
Info
Novell Access Manager Local Browser Security Bypass Vulnerability
| Bugtraq ID: | 32121 |
| Class: | Design Error |
| CVE: |
CVE-2008-6722 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 05 2008 12:00AM |
| Updated: | Apr 23 2009 02:26PM |
| Credit: | This issue was disclosed by the vendor. |
| Vulnerable: |
Novell Access Manager 3 SP4 Novell Access Manager 3 SP1 Novell Access Manager 3 |
| Not Vulnerable: | |
Discussion
Novell Access Manager Local Browser Security Bypass Vulnerability
Novell Access Manager is prone to a local security-bypass vulnerability because it fails to adequately clean up the browser's SSL cache during logout operations.
Successfully exploiting this issue allows an attacker with physical access to the computer to take over the previous user's session without being prompted to log in again. This can aid in launching further attacks.
Novell Access Manager is prone to a local security-bypass vulnerability because it fails to adequately clean up the browser's SSL cache during logout operations.
Successfully exploiting this issue allows an attacker with physical access to the computer to take over the previous user's session without being prompted to log in again. This can aid in launching further attacks.
Exploit / POC
Novell Access Manager Local Browser Security Bypass Vulnerability
To exploit this issue, an attacker needs physical access to an affected computer.
To exploit this issue, an attacker needs physical access to an affected computer.
Solution / Fix
Novell Access Manager Local Browser Security Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Novell Access Manager Local Browser Security Bypass Vulnerability
References:
References: