PT-2009-5214 · Sun · Sun Virtual Desktop Infrastructure
Publicado
2009-08-18
·
Atualizado
2009-08-21
·
CVE-2009-2856
CVSS v2.0
3.5
Baixa
| Vetor | AV:N/AC:M/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Sun Virtual Desktop Infrastructure (VDI) version 3.0
Description
The issue occurs when anonymous binding is enabled, and the software fails to properly handle a client's attempt to establish an authenticated and encrypted connection. This might allow remote attackers to read cleartext VDI configuration-data requests by sniffing LDAP sessions on the network.
Recommendations
For Sun Virtual Desktop Infrastructure (VDI) version 3.0, consider disabling anonymous binding to prevent remote attackers from reading cleartext VDI configuration-data requests. As a temporary workaround, restrict access to the LDAP sessions on the network to minimize the risk of exploitation.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sun Virtual Desktop Infrastructure