PT-2009-5214 · Sun · Sun Virtual Desktop Infrastructure
Published
2009-08-18
·
Updated
2009-08-21
·
CVE-2009-2856
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Sun Virtual Desktop Infrastructure (VDI) version 3.0
Description
The issue occurs when anonymous binding is enabled, and the software fails to properly handle a client's attempt to establish an authenticated and encrypted connection. This might allow remote attackers to read cleartext VDI configuration-data requests by sniffing LDAP sessions on the network.
Recommendations
For Sun Virtual Desktop Infrastructure (VDI) version 3.0, consider disabling anonymous binding to prevent remote attackers from reading cleartext VDI configuration-data requests. As a temporary workaround, restrict access to the LDAP sessions on the network to minimize the risk of exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sun Virtual Desktop Infrastructure