PT-2007-1942 · Oracle · Sun Ray Server
Published
2007-01-25
·
Updated
2017-07-29
·
CVE-2007-0482
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Sun Ray Server Software versions 2.0 through 3.0 before 20070123
Description
The issue allows local users to obtain the utadmin password by reading a web server's log file or by conducting a different local attack. This is related to the cgi-bin/main component.
Recommendations
For Sun Ray Server Software versions 2.0 through 3.0 before 20070123, update to a version released after 20070123 to resolve the issue. As a temporary workaround, consider restricting access to the log files of the web server and limiting local user privileges to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sun Ray Server