Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Novell Access Manager 3 SP4 does not properly expire X.509 certificate sessions, which allows physically proximate attackers to obtain a logged-in session by using a victim's web-browser process that continues to send the original and valid SSL sessionID, related to inability of Apache Tomcat to clear entries from its SSL cache.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Novell Access Manager X509会话绕过认证漏洞
Vulnerability Description
Novell Access Manager是新一代的访问管理解决方案。 如果用户在认证到Novell Access Manager时使用的是标准Novell X509认证类,且该认证使用了储存在智能卡或浏览器证书存储中的证书,在证书验证过程成功后用户就会在浏览器中看到目标页面。之后用户需要注销Access Manager的话,就会点击注销链接(在Access Gateway中为/AGLogout,在Identity Server中为/nidp/app/plogout),然后得到消息说明用户已经成功的注销。
CVSS Information
N/A
Vulnerability Type
N/A