PT-2009-5214 · Sun · Sun Virtual Desktop Infrastructure

Published

2009-08-18

·

Updated

2009-08-21

·

CVE-2009-2856

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Sun Virtual Desktop Infrastructure (VDI) version 3.0
Description The issue occurs when anonymous binding is enabled, and the software fails to properly handle a client's attempt to establish an authenticated and encrypted connection. This might allow remote attackers to read cleartext VDI configuration-data requests by sniffing LDAP sessions on the network.
Recommendations For Sun Virtual Desktop Infrastructure (VDI) version 3.0, consider disabling anonymous binding to prevent remote attackers from reading cleartext VDI configuration-data requests. As a temporary workaround, restrict access to the LDAP sessions on the network to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-2856

Affected Products

Sun Virtual Desktop Infrastructure