SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2008-5423

Sun Sun Ray Server Software 3.x and 4.0 and Sun Ray Windows Connector 1.1 and 2.0 expose the LDAP password during a configuration step, which allows local users to discover the Sun Ray administration password, and obtain admin access to the Data Store…

MEDIUM 4.3EPSS 0.32%

Does this matter?

Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.

Description

Sun Sun Ray Server Software 3.x and 4.0 and Sun Ray Windows Connector 1.1 and 2.0 expose the LDAP password during a configuration step, which allows local users to discover the Sun Ray administration password, and obtain admin access to the Data Store and Administration GUI, via unspecified vectors related to the utconfig component of the Server Software and the uttscadm component of the Windows Connector.

CVSS 2.0
4.3 MEDIUMAV:L/AC:L/Au:S/C:P/I:P/A:P
EPSS
0.32% probability · 24th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
sun/ray server software · sun/ray windows connector
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.