CVE Vulnerabilities

CVE-2006-0511

Published: Feb 01, 2006 | Modified: May 17, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:L/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Blackboard Academic Suite 6.0 and earlier does not properly clear session information when de-authenticating a user who is idle, which allows subsequent users to log in as the previous user and gain privileges. NOTE: the vendor has disputed this issue, saying that This is a customer specific issue related to their Kerberos authentication single sign-on application and not a vulnerability in the Blackboard product.

Affected Software

Name Vendor Start Version End Version
Blackboard Blackboard 5.0 (including) 5.0 (including)
Blackboard Blackboard 5.0.2 (including) 5.0.2 (including)
Blackboard Blackboard 5.5 (including) 5.5 (including)
Blackboard Blackboard 5.5.1 (including) 5.5.1 (including)
Blackboard Blackboard 6.0 (including) 6.0 (including)
Blackboard_academic_suite Blackboard 6.0 (including) 6.0 (including)

References