cbcvebase.
CVE-2009-4655
published 2010-02-26

CVE-2009-4655: The dhost web service in Novell eDirectory 8.8.5 uses a predictable session cookie, which makes it easier for remote attackers to hijack sessions via a…

PriorityP354high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
49.86%
98.8th percentile
The dhost web service in Novell eDirectory 8.8.5 uses a predictable session cookie, which makes it easier for remote attackers to hijack sessions via a modified cookie.

Affected

1 ranges
VendorProductVersion rangeFixed in
novelledirectory

Detection & IOCsextracted from sources · hover to see the quote

port8030
url/dhost/
cookiePredictable hex session cookie (format: <name>=<8-hex-digit value>)
  • Flag unauthenticated GET /dhost/ requests over SSL on port 8030 that do not carry a valid prior session, especially when the cookie value presented matches a predicted increment of a recently issued cookie.
  • ·The exploit module defaults to SSL=true on port 8030; detection rules must inspect TLS-decrypted traffic to observe the cookie values and request patterns.
  • ·The predictability check may fail if the target has been patched — the module itself reports this condition, so absence of a uniform delta does not guarantee safety without patch verification.
  • ·Only Novell eDirectory 8.8.5 is confirmed vulnerable; other versions may also be affected and should be assessed.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.