PT-2008-6540 · Sun · Sun Ray Windows Connector+1
Published
2008-12-11
·
Updated
2018-10-30
·
CVE-2008-5423
CVSS v2.0
4.3
Medium
| Vector | AV:L/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Sun Sun Ray Server Software versions 3.x through 4.0
Sun Ray Windows Connector versions 1.1 through 2.0
Description
The issue allows local users to discover the Sun Ray administration password, which can lead to obtaining admin access to the Data Store and Administration GUI. This is related to the utconfig component of the Server Software and the uttscadm component of the Windows Connector.
Recommendations
For Sun Sun Ray Server Software versions 3.x through 4.0, consider restricting access to the utconfig component until a fix is available.
For Sun Ray Windows Connector versions 1.1 through 2.0, consider disabling the uttscadm component as a temporary workaround to minimize the risk of exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sun Ray Windows Connector
Sun Ray Server