Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2008-6722

EPSS 0.07% · P21
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2008-6722

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Novell Access Manager 3 SP4 does not properly expire X.509 certificate sessions, which allows physically proximate attackers to obtain a logged-in session by using a victim's web-browser process that continues to send the original and valid SSL sessionID, related to inability of Apache Tomcat to clear entries from its SSL cache.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Novell Access Manager X509会话绕过认证漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Novell Access Manager是新一代的访问管理解决方案。 如果用户在认证到Novell Access Manager时使用的是标准Novell X509认证类,且该认证使用了储存在智能卡或浏览器证书存储中的证书,在证书验证过程成功后用户就会在浏览器中看到目标页面。之后用户需要注销Access Manager的话,就会点击注销链接(在Access Gateway中为/AGLogout,在Identity Server中为/nidp/app/plogout),然后得到消息说明用户已经成功的注销。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2008-6722

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2008-6722

登录查看更多情报信息。

Same Patch Batch · n/a · 2009-04-14 · 6 CVEs total

CVE-2008-6721Ajsquare AJ Article 'index.php'SQL注入漏洞
CVE-2008-6723TurnkeyForms Entertainment Portal Cookie身份认证绕过漏洞
CVE-2009-0792Artifex Software Ghostscript 数字错误漏洞
CVE-2009-1292IBM Rational ClearCase 信息泄露漏洞
CVE-2009-0159NTP ntpq命令远程栈溢出溢出漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2008-6722

No comments yet


Leave a comment