Unrated severityNVD Advisory· Published Mar 23, 2006· Updated Apr 16, 2026
CVE-2006-0997
CVE-2006-0997
Description
The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) permits encryption with a NULL key, which results in cleartext communication that allows remote attackers to read an SSL protected session by sniffing network traffic.
Affected products
8- cpe:2.3:o:novell:open_enterprise_server:*:*:*:*:*:*:*:*
cpe:2.3:o:novell:netware:6.5:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:o:novell:netware:6.5:*:*:*:*:*:*:*
- cpe:2.3:o:novell:netware:6.5:sp1:*:*:*:*:*:*
- cpe:2.3:o:novell:netware:6.5:sp1.1a:*:*:*:*:*:*
- cpe:2.3:o:novell:netware:6.5:sp1.1b:*:*:*:*:*:*
- cpe:2.3:o:novell:netware:6.5:sp2:*:*:*:*:*:*
- cpe:2.3:o:novell:netware:6.5:sp3:*:*:*:*:*:*
- cpe:2.3:o:novell:netware:6.5:sp4:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7News mentions
0No linked articles in our index yet.