PT-2008-6540 · Sun · Sun Ray Windows Connector+1

Publicado

2008-12-11

·

Atualizado

2018-10-30

·

CVE-2008-5423

CVSS v2.0

4.3

Média

VetorAV:L/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Sun Sun Ray Server Software versions 3.x through 4.0 Sun Ray Windows Connector versions 1.1 through 2.0
Description The issue allows local users to discover the Sun Ray administration password, which can lead to obtaining admin access to the Data Store and Administration GUI. This is related to the utconfig component of the Server Software and the uttscadm component of the Windows Connector.
Recommendations For Sun Sun Ray Server Software versions 3.x through 4.0, consider restricting access to the utconfig component until a fix is available. For Sun Ray Windows Connector versions 1.1 through 2.0, consider disabling the uttscadm component as a temporary workaround to minimize the risk of exploitation.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-5423

Produtos afetados

Sun Ray Windows Connector
Sun Ray Server