First published: Fri Feb 26 2010(Updated: )
The dhost web service in Novell eDirectory 8.8.5 uses a predictable session cookie, which makes it easier for remote attackers to hijack sessions via a modified cookie.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microfocus eDirectory | =8.8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4655 has a high severity due to its potential for session hijacking.
To fix CVE-2009-4655, update Novell eDirectory to a version that addresses the predictable session cookie vulnerability.
CVE-2009-4655 allows attackers to hijack user sessions by exploiting the predictable session cookie.
CVE-2009-4655 specifically affects Novell eDirectory version 8.8.5.
A potential workaround for CVE-2009-4655 includes employing secure cookie settings to limit exposure to session hijacking.