CVE-2006-0999

Novell NetWare 6.5-Open Enterprise Server - Info Disclosure

Title source: llm

Description

The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) allows a client to force the server to use weak encryption by stating that a weak cipher is required for client compatibility, which might allow remote attackers to decrypt contents of an SSL protected session.

Scores

EPSS 0.0046
EPSS Percentile 63.5%

Classification

Status draft

Affected Products (8)

novell/open_enterprise_server
novell/netware
novell/netware
novell/netware
novell/netware
novell/netware
novell/netware
novell/netware

Timeline

Published Mar 23, 2006
Tracked Since Feb 18, 2026