CVE-2009-4440

medium

Description

Directory Proxy Server (DPS) in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 does not properly handle multiple client connections within a short time window, which allows remote attackers to hijack the backend connection of an authenticated user, and obtain the privileges of this user, by making a client connection in opportunistic circumstances, related to "long binds," aka Bug Ids 6828462 and 6823593.

References

http://www.vupen.com/english/advisories/2009/3647

http://www.securitytracker.com/id?1023389

http://www.securityfocus.com/bid/37481

http://sunsolve.sun.com/search/document.do?assetkey=1-66-270789-1

http://sunsolve.sun.com/search/document.do?assetkey=1-21-141958-01-1

http://secunia.com/advisories/37915

Details

Source: Mitre, NVD

Published: 2009-12-28

Updated: 2010-06-13

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Severity: Medium