Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.902011
Categoría:Denial of Service
Título:Sun Java System DSEE Multiple Vulnerabilities (Windows)
Resumen:This host is running Sun Java System Directory Server Enterprise; Edition (DSEE) and is prone to multiple vulnerabilities.
Descripción:Summary:
This host is running Sun Java System Directory Server Enterprise
Edition (DSEE) and is prone to multiple vulnerabilities.

Vulnerability Insight:
- An error in Directory Proxy Server may cause a client operation to
temporarily run with another client's privileges.

- An error in Directory Proxy Server can be exploited via specially crafted
packets to cause the service to stop responding to new client connections.

- An error in Directory Proxy Server can be exploited via a specially crafted
'psearch' client to exhaust available CPU resources, preventing the server
from sending results to other 'psearch' clients.

Vulnerability Impact:
Successful exploitation will allow attacker to gain knowledge of potentially
sensitive information or cause a Denial of Service.

Affected Software/OS:
Sun Java System DSEE version 6.0 through 6.3.1 on Windows.

Solution:
Apply patch 141958-01 or later for Sun Java System DSEE version 6.3.1.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Referencia Cruzada: BugTraq ID: 37481
Common Vulnerability Exposure (CVE) ID: CVE-2009-4440
http://www.securityfocus.com/bid/37481
http://www.securitytracker.com/id?1023389
http://secunia.com/advisories/37915
http://sunsolve.sun.com/search/document.do?assetkey=1-66-270789-1
http://www.vupen.com/english/advisories/2009/3647
Common Vulnerability Exposure (CVE) ID: CVE-2009-4441
Common Vulnerability Exposure (CVE) ID: CVE-2009-4442
Common Vulnerability Exposure (CVE) ID: CVE-2009-4443
CopyrightCopyright (C) 2010 Greenbone Networks GmbH

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.