CVE-2008-5422
Summary
| CVE | CVE-2008-5422 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-12-11 15:30:00 UTC |
| Updated | 2018-10-30 16:25:00 UTC |
| Description | Sun Sun Ray Server Software 3.1 through 4.0 does not properly restrict access, which allows remote attackers to discover the Sun Ray administration password, and obtain admin access to the Data Store and Administration GUI, via unspecified vectors. |
Risk And Classification
Problem Types: CWE-264
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Novell | Suse Linux Enterprise Server | 8 | All | All | All |
| Operating System | Novell | Suse Linux Enterprise Server | 9 | All | All | All |
| Operating System | Novell | Suse Linux Enterprise Server | 8 | All | All | All |
| Operating System | Novell | Suse Linux Enterprise Server | 9 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 3 | All | advanced_server | All |
| Operating System | Redhat | Enterprise Linux | 4 | All | advanced_server | All |
| Operating System | Redhat | Enterprise Linux | 3 | All | advanced_server | All |
| Operating System | Redhat | Enterprise Linux | 4 | All | advanced_server | All |
| Application | Sun | Java Desktop System | 2.0 | All | All | All |
| Application | Sun | Java Desktop System | 2.0 | All | All | All |
| Application | Sun | Ray Server Software | 3.0 | All | linux | All |
| Application | Sun | Ray Server Software | 3.0 | All | sparc | All |
| Application | Sun | Ray Server Software | 3.1 | All | linux | All |
| Application | Sun | Ray Server Software | 3.1 | All | sparc | All |
| Application | Sun | Ray Server Software | 3.1 | All | x86 | All |
| Application | Sun | Ray Server Software | 3.1.1 | All | linux | All |
| Application | Sun | Ray Server Software | 4.0 | All | linux | All |
| Application | Sun | Ray Server Software | 4.0 | All | sparc | All |
| Application | Sun | Ray Server Software | 4.0 | All | x86 | All |
| Application | Sun | Ray Server Software | 3.0 | All | linux | All |
| Application | Sun | Ray Server Software | 3.0 | All | sparc | All |
| Application | Sun | Ray Server Software | 3.1 | All | linux | All |
| Application | Sun | Ray Server Software | 3.1 | All | sparc | All |
| Application | Sun | Ray Server Software | 3.1 | All | x86 | All |
| Application | Sun | Ray Server Software | 3.1.1 | All | linux | All |
| Application | Sun | Ray Server Software | 4.0 | All | linux | All |
| Application | Sun | Ray Server Software | 4.0 | All | sparc | All |
| Application | Sun | Ray Server Software | 4.0 | All | x86 | All |
| Operating System | Sun | Solaris | 10 | All | sparc | All |
| Operating System | Sun | Solaris | 10 | All | x86 | All |
| Operating System | Sun | Solaris | 8 | All | sparc | All |
| Operating System | Sun | Solaris | 9 | All | sparc | All |
| Operating System | Sun | Solaris | 10 | All | sparc | All |
| Operating System | Sun | Solaris | 10 | All | x86 | All |
| Operating System | Sun | Solaris | 8 | All | sparc | All |
| Operating System | Sun | Solaris | 9 | All | sparc | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Sun Ray Server Software Two Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | SECUNIA | secunia.com | |
| Sun Ray Server Lets Remote Users Obtain the Administrative Password in Certain Cases - SecurityTracker | SECTRACK | www.securitytracker.com | |
| sunsolve.sun.com/search/document.do | CONFIRM | sunsolve.sun.com | Patch, Vendor Advisory |
| ASA-2008-502 (SUN 240365) | CONFIRM | support.avaya.com | |
| 240365 | SUNALERT | sunsolve.sun.com | Patch, Vendor Advisory |
| Sun Ray Server Administration Password Information Disclosure Vulnerability | BID | www.securityfocus.com | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.