CVE-2009-2856
Severity CVSS v4.0:
Pending analysis
Type:
CWE-200
Information Leak / Disclosure
Publication date:
18/08/2009
Last modified:
09/04/2025
Description
Sun Virtual Desktop Infrastructure (VDI) 3.0, when anonymous binding is enabled, does not properly handle a client's attempt to establish an authenticated and encrypted connection, which might allow remote attackers to read cleartext VDI configuration-data requests by sniffing LDAP sessions on the network.
Impact
Base Score 2.0
3.50
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:sun:virtual_desktop_infrastructure:3.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:sun:solaris:10.0:*:x86:*:*:*:*:* | ||
| cpe:2.3:a:sun:virtual_desktop_infrastructure:3.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:sun:solaris:10.0:*:sparc:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://secunia.com/advisories/36330
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-141481-02-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-265488-1
- http://www.vupen.com/english/advisories/2009/2282
- http://secunia.com/advisories/36330
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-141481-02-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-265488-1
- http://www.vupen.com/english/advisories/2009/2282



