Vulnerability record · CVE-2009-4655 · published 26 February 2010
CVE-2009-4655: Novell eDirectory dhost predictable session cookie allows hijacking
Novell · Edirectory
The dhost web service in Novell eDirectory 8.8.5 generates session cookies from a predictable value, so an attacker who can guess or modify a cookie can take over an existing session. Because the cookie is the only session identifier, predictability undermines the authentication boundary of the dhost service.
Description
The dhost web service in Novell eDirectory 8.8.5 uses a predictable session cookie, which makes it easier for remote attackers to hijack sessions via a modified cookie.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityNetwork-reachable, no authentication required, public exploit code exists, and EPSS is near the top percentile, though the flaw is limited to session hijacking of the dhost service.
What it is
The dhost web service in Novell eDirectory 8.8.5 generates session cookies from a predictable value, so an attacker who can guess or modify a cookie can take over an existing session. Because the cookie is the only session identifier, predictability undermines the authentication boundary of the dhost service.
Impact
An attacker gains the privileges of a hijacked dhost session, which can include reading and modifying directory data depending on the victim's role. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as partial.
Attack surface
Reachable over the network through the dhost web service (AV:N, AC:L, Au:N), with no authentication and no user interaction required to attempt cookie manipulation. The record does not state which port or interface dhost listens on.
Exploitation
A public Metasploit auxiliary module for the eDirectory dhost cookie exists, indicating exploit code is available; the CVE is not in CISA KEV, and EPSS shows a 30-day probability of about 0.50 (98.8th percentile).
What to do
- Upgrade or patch Novell eDirectory beyond 8.8.5, or apply the vendor fix for the dhost session cookie issue, and verify the dhost service version after patching.
- If dhost is not required, disable or block the dhost web service and restrict network access to it.
- Replace predictable session identifiers with cryptographically random values and enforce server-side session validation.
- Force re-authentication and invalidate existing sessions after applying the fix, since previously issued cookies may remain guessable.
- Monitor for repeated or malformed cookie values against the dhost service and rate-limit or block offending sources.
Detection
- Inspect dhost web service logs for repeated requests with altered or sequential session cookie values from the same source.
- Alert on Metasploit auxiliary/admin/edirectory/edirectory_dhost_cookie activity or matching request patterns at the network perimeter.
- Baseline normal dhost session cookie formats and flag cookies that deviate from the expected random pattern.
- Correlate dhost access with authentication events to find sessions used without a corresponding login.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-4655 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-4655), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.