4.3

CVE-2008-5423

Sun Sun Ray Server Software 3.x and 4.0 and Sun Ray Windows Connector 1.1 and 2.0 expose the LDAP password during a configuration step, which allows local users to discover the Sun Ray administration password, and obtain admin access to the Data Store and Administration GUI, via unspecified vectors related to the utconfig component of the Server Software and the uttscadm component of the Windows Connector.

Data is provided by the National Vulnerability Database (NVD)
SunRay Server Software Version3.0 Editionsparc
   SunSolaris Version8 Editionsparc
   SunSolaris Version9 Editionsparc
   SunSolaris Version10 Editionsparc
SunRay Server Software Version3.1 Editionsparc
   SunSolaris Version8 Editionsparc
   SunSolaris Version9 Editionsparc
   SunSolaris Version10 Editionsparc
SunRay Server Software Version4.0 Editionsparc
   SunSolaris Version8 Editionsparc
   SunSolaris Version9 Editionsparc
   SunSolaris Version10 Editionsparc
SunRay Server Software Version3.1 Editionx86
   SunSolaris Version10 Editionx86
SunRay Server Software Version4.0 Editionx86
   SunSolaris Version10 Editionx86
SunRay Windows Connector Version1.1 Editionsparc
SunRay Windows Connector Version2.0 Editionsparc
SunRay Server Software Version3.1 Editionsparc
SunRay Server Software Version4.0 Editionsparc
SunRay Windows Connector Version1.1 Editionx86
SunRay Windows Connector Version2.0 Editionx86
SunRay Server Software Version3.1 Editionx86
SunRay Server Software Version4.0 Editionx86
SunRay Windows Connector Version1.1 Editionlinux
SunRay Windows Connector Version2.0 Editionlinux
SunRay Server Software Version3.1.1 Editionlinux
SunRay Server Software Version4.0 Editionlinux
SunRay Server Software Version3.1.1 Editionlinux
   NovellSuse Linux Enterprise Server Version9
   RedhatEnterprise Linux Version4 Editionadvanced_server
SunRay Server Software Version4.0 Editionlinux
   NovellSuse Linux Enterprise Server Version9
   RedhatEnterprise Linux Version4 Editionadvanced_server
SunRay Server Software Version3.0 Editionlinux
   SunJava Desktop System Version2.0
   NovellSuse Linux Enterprise Server Version8
   RedhatEnterprise Linux Version3 Editionadvanced_server
SunRay Server Software Version3.1 Editionlinux
   SunJava Desktop System Version2.0
   NovellSuse Linux Enterprise Server Version8
   RedhatEnterprise Linux Version3 Editionadvanced_server
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.08% 0.24
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 3.1 6.4
AV:L/AC:L/Au:S/C:P/I:P/A:P
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.