MEDIUM · 4.3

CVE-2006-0511

Blackboard Academic Suite 6.0 and earlier does not properly clear session information when de-authenticating a user who is idle, which allows subsequent users to log in as the previous user and gain p...

Vulnerability Description

Blackboard Academic Suite 6.0 and earlier does not properly clear session information when de-authenticating a user who is idle, which allows subsequent users to log in as the previous user and gain privileges. NOTE: the vendor has disputed this issue, saying that "This is a customer specific issue related to their Kerberos authentication single sign-on application and not a vulnerability in the Blackboard product.

CVSS Score

4.3

MEDIUM

AV:L/AC:L/Au:S/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
BlackboardBlackboard5.0
BlackboardBlackboard Academic Suite6.0

References

FAQ

What is CVE-2006-0511?

CVE-2006-0511 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Blackboard Academic Suite 6.0 and earlier does not properly clear session information when de-authenticating a user who is idle, which allows subsequent users to log in as the previous user and gain p...

How severe is CVE-2006-0511?

CVE-2006-0511 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-0511?

Check the references section above for vendor advisories and patch information. Affected products include: Blackboard Blackboard, Blackboard Blackboard Academic Suite.