CVE-2008-5422
Summary
| CVE | CVE-2008-5422 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-12-11 15:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Sun Sun Ray Server Software 3.1 through 4.0 does not properly restrict access, which allows remote attackers to discover the Sun Ray administration password, and obtain admin access to the Data Store and Administration GUI, via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Novell | Suse Linux Enterprise Server | 8 | All | All | All |
| Operating System | Novell | Suse Linux Enterprise Server | 9 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 3 | All | advanced_server | All |
| Operating System | Redhat | Enterprise Linux | 4 | All | advanced_server | All |
| Application | Sun | Java Desktop System | 2.0 | All | All | All |
| Application | Sun | Ray Server Software | 3.0 | All | linux | All |
| Application | Sun | Ray Server Software | 3.0 | All | sparc | All |
| Application | Sun | Ray Server Software | 3.1 | All | linux | All |
| Application | Sun | Ray Server Software | 3.1 | All | sparc | All |
| Application | Sun | Ray Server Software | 3.1 | All | x86 | All |
| Application | Sun | Ray Server Software | 3.1.1 | All | linux | All |
| Application | Sun | Ray Server Software | 4.0 | All | linux | All |
| Application | Sun | Ray Server Software | 4.0 | All | sparc | All |
| Application | Sun | Ray Server Software | 4.0 | All | x86 | All |
| Operating System | Sun | Solaris | 10 | All | sparc | All |
| Operating System | Sun | Solaris | 10 | All | x86 | All |
| Operating System | Sun | Solaris | 8 | All | sparc | All |
| Operating System | Sun | Solaris | 9 | All | sparc | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Sun Ray Server Administration Password Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| Sun Ray Server Software Two Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | Patch, Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| ASA-2008-502 (SUN 240365) | af854a3a-2127-422b-91ae-364da2661108 | support.avaya.com | |
| Sun Ray Server Lets Remote Users Obtain the Administrative Password in Certain Cases - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.