[SA47268] Novell Access Manager SSL/TLS Initialization Vector Selection Weakness

SecuritySECUNIA ADVISORY ID:
SA47268

VERIFY ADVISORY:
Secunia.com
http://secunia.com/advisories/47268/
Customer Area (Credentials Required)
https://ca.secunia.com/?page=viewadvisory&vuln_id=47268

RELEASE DATE:
2011-12-16

DISCUSS ADVISORY:
http://secunia.com/advisories/47268/#comments

DESCRIPTION:
A weakness has been reported in Novell Access Manager, which can be
exploited by malicious people to disclose potentially sensitive
information and hijack a user's session.

A design error exists within the implementation of SSL 3.0 and TLS
1.0 protocols.

For more information:
SA46168

The weakness is reported in version 3.1.

SOLUTION:
Edit configuration to enable RC4 encryption or ensure that clients
use an updated browser (please see the vendor's advisory for more
information).

ORIGINAL ADVISORY:
http://www.novell.com/support/viewContent.do?externalId=7009901

[SA47268] Novell Access Manager SSL/TLS Initialization Vector Selection Weakness
comments (0)
The following comments are owned by whomever posted them. This site is not responsible for what they say.

Trackback

Trackback URL for this entry: http://www.abend.org/trackback.php/20111217095204400

No trackback comments for this entry.

User Functions





Don't have an account yet? Sign up as a New User

Lost your password?

What's New

Stories

No new stories

Comments last 2 days

No new comments

Trackbacks last 2 days

No new trackback comments

Links last 2 weeks

No recent new links

REVIEWS last 2 weeks

No recent new reviews

Who's Online

Guest Users: 7

Live Novell Chat

Live Novell Chat

Topics

  • Home
  • Linux/Open Source (312/0)
  • GroupWise (164/0)
  • Administration (78/0)
  • NDS/eDir (21/0)
  • Certification (33/0)
  • NetWare (59/0)
  • FAQ (1/0)
  • Contracting (2/0)
  • Way Off Topic! (2/0)
  • Poll posts (1/0)
  • General News (937/0)
  • Resources (21/0)
  • Security (309/0)
  • Poll

    Brainshare 2013

    How many of you are attending BS2013?

    •  Yes, I am!
    •  No, I am not, but hope to next year
    •  No, I am not, do not plan to attend any year

    Results
    Other polls | 9 voters | 0 comments

    Microsoft Security