CVE-2009-4442

high

Description

Directory Proxy Server (DPS) in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 does not properly implement the max-client-connections configuration setting, which allows remote attackers to cause a denial of service (connection slot exhaustion) by making multiple connections and performing no operations on these connections, aka Bug Id 6648665.

References

http://www.vupen.com/english/advisories/2009/3647

http://www.securitytracker.com/id?1023389

http://www.securityfocus.com/bid/37481

http://sunsolve.sun.com/search/document.do?assetkey=1-66-270789-1

http://sunsolve.sun.com/search/document.do?assetkey=1-21-141958-01-1

http://secunia.com/advisories/37915

Details

Source: Mitre, NVD

Published: 2009-12-28

Updated: 2010-06-13

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

Severity: Medium

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Severity: High