4.3
CVE-2008-5423
- EPSS 0.32%
- Veröffentlicht 11.12.2008 15:30:00
- Zuletzt bearbeitet 16.06.2026 22:59:56
- Erkennungen
Sun Sun Ray Server Software 3.x and 4.0 and Sun Ray Windows Connector 1.1 and 2.0 expose the LDAP password during a configuration step, which allows local users to discover the Sun Ray administration password, and obtain admin access to the Data Store and Administration GUI, via unspecified vectors related to the utconfig component of the Server Software and the uttscadm component of the Windows Connector.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sun ≫ Ray Server Software Version 3.0 Edition sparc
Sun ≫ Ray Server Software Version 3.1 Edition sparc
Sun ≫ Ray Server Software Version 4.0 Edition sparc
Sun ≫ Ray Server Software Version 3.1 Edition x86
Sun ≫ Ray Server Software Version 4.0 Edition x86
Sun ≫ Ray Windows Connector Version 1.1 Edition sparc
Sun ≫ Ray Windows Connector Version 2.0 Edition sparc
Sun ≫ Ray Server Software Version 3.1 Edition sparc
Sun ≫ Ray Server Software Version 4.0 Edition sparc
Sun ≫ Ray Windows Connector Version 1.1 Edition x86
Sun ≫ Ray Windows Connector Version 2.0 Edition x86
Sun ≫ Ray Server Software Version 3.1 Edition x86
Sun ≫ Ray Server Software Version 4.0 Edition x86
Sun ≫ Ray Windows Connector Version 1.1 Edition linux
Sun ≫ Ray Windows Connector Version 2.0 Edition linux
Sun ≫ Ray Server Software Version 3.1.1 Edition linux
Sun ≫ Ray Server Software Version 4.0 Edition linux
Sun ≫ Ray Server Software Version 3.1.1 Edition linux
Novell ≫ Suse Linux Enterprise Server Version 9
Redhat ≫ Enterprise Linux Version 4 Edition advanced_server
Redhat ≫ Enterprise Linux Version 4 Edition advanced_server
Sun ≫ Ray Server Software Version 4.0 Edition linux
Novell ≫ Suse Linux Enterprise Server Version 9
Redhat ≫ Enterprise Linux Version 4 Edition advanced_server
Redhat ≫ Enterprise Linux Version 4 Edition advanced_server
Sun ≫ Ray Server Software Version 3.0 Edition linux
Sun ≫ Java Desktop System Version 2.0
Novell ≫ Suse Linux Enterprise Server Version 8
Redhat ≫ Enterprise Linux Version 3 Edition advanced_server
Novell ≫ Suse Linux Enterprise Server Version 8
Redhat ≫ Enterprise Linux Version 3 Edition advanced_server
Sun ≫ Ray Server Software Version 3.1 Edition linux
Sun ≫ Java Desktop System Version 2.0
Novell ≫ Suse Linux Enterprise Server Version 8
Redhat ≫ Enterprise Linux Version 3 Edition advanced_server
Novell ≫ Suse Linux Enterprise Server Version 8
Redhat ≫ Enterprise Linux Version 3 Edition advanced_server
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.32% | 0.231 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 3.1 | 6.4 |
AV:L/AC:L/Au:S/C:P/I:P/A:P
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://secunia.com/advisories/33108
http://sunsolve.sun.com/search/document.do?assetkey=1-21-127553-04-1
http://www.vupen.com/english/advisories/2008/3406
http://secunia.com/advisories/33119
http://securitytracker.com/id?1021379
http://sunsolve.sun.com/search/document.do?assetkey=1-21-127556-03-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-240506-1
http://support.avaya.com/elmodocs2/security/ASA-2008-500.htm
http://www.securityfocus.com/bid/32772
http://www.vupen.com/english/advisories/2008/3407
https://exchange.xforce.ibmcloud.com/vulnerabilities/47258