PT-2009-5214 · Sun · Sun Virtual Desktop Infrastructure

Publicado

2009-08-18

·

Atualizado

2009-08-21

·

CVE-2009-2856

CVSS v2.0

3.5

Baixa

VetorAV:N/AC:M/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Sun Virtual Desktop Infrastructure (VDI) version 3.0
Description The issue occurs when anonymous binding is enabled, and the software fails to properly handle a client's attempt to establish an authenticated and encrypted connection. This might allow remote attackers to read cleartext VDI configuration-data requests by sniffing LDAP sessions on the network.
Recommendations For Sun Virtual Desktop Infrastructure (VDI) version 3.0, consider disabling anonymous binding to prevent remote attackers from reading cleartext VDI configuration-data requests. As a temporary workaround, restrict access to the LDAP sessions on the network to minimize the risk of exploitation.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-2856

Produtos afetados

Sun Virtual Desktop Infrastructure