CVE-2008-5423
Summary
| CVE | CVE-2008-5423 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-12-11 15:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Sun Sun Ray Server Software 3.x and 4.0 and Sun Ray Windows Connector 1.1 and 2.0 expose the LDAP password during a configuration step, which allows local users to discover the Sun Ray administration password, and obtain admin access to the Data Store and Administration GUI, via unspecified vectors related to the utconfig component of the Server Software and the uttscadm component of the Windows Connector. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sun | Ray Server Software | 3.0 | All | sparc | All |
| Application | Sun | Ray Server Software | 3.1 | All | sparc | All |
| Application | Sun | Ray Server Software | 3.1 | All | x86 | All |
| Application | Sun | Ray Server Software | 4.0 | All | sparc | All |
| Application | Sun | Ray Server Software | 4.0 | All | x86 | All |
| Application | Sun | Ray Windows Connector | 1.1 | All | sparc | All |
| Application | Sun | Ray Windows Connector | 2.0 | All | sparc | All |
| Operating System | Sun | Solaris | 10 | All | sparc | All |
| Operating System | Sun | Solaris | 10 | All | x86 | All |
| Operating System | Sun | Solaris | 8 | All | sparc | All |
| Operating System | Sun | Solaris | 9 | All | sparc | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Sun Ray Server and Sun Ray Windows Connector Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | Patch |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Sun Ray Server Lets Local Users Obtain the Administrative Password in Certain Cases - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | Patch, Vendor Advisory |
| Sun Ray Server Software Two Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| ASA-2008-500 (SUN 240506) | af854a3a-2127-422b-91ae-364da2661108 | support.avaya.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Sun Ray Windows Connector Information Disclosure Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.