CVE-2006-0997

Novell NetWare <6.5 - Info Disclosure

Title source: llm

Description

The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) permits encryption with a NULL key, which results in cleartext communication that allows remote attackers to read an SSL protected session by sniffing network traffic.

Scores

EPSS 0.0027
EPSS Percentile 49.6%

Classification

Status draft

Affected Products (8)

novell/open_enterprise_server
novell/netware
novell/netware
novell/netware
novell/netware
novell/netware
novell/netware
novell/netware

Timeline

Published Mar 23, 2006
Tracked Since Feb 18, 2026