CVE-2009-0609
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
17/02/2009
Last modified:
09/04/2025
Description
Sun Java System Directory Proxy Server in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3, when a JDBC data source is used, does not properly handle (1) a long value in an ADD or (2) long string attributes, which allows remote attackers to cause a denial of service (JDBC backend outage) via crafted LDAP requests.
Impact
Base Score 2.0
7.80
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:sun:java_system_directory_server:6.0:enterprise:*:*:*:*:*:* | ||
| cpe:2.3:a:sun:java_system_directory_server:6.1:enterprise:*:*:*:*:*:* | ||
| cpe:2.3:a:sun:java_system_directory_server:6.2:enterprise:*:*:*:*:*:* | ||
| cpe:2.3:a:sun:java_system_directory_server:6.3:enterprise:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://secunia.com/advisories/33923
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-125276-08-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-251086-1
- http://www.securityfocus.com/bid/33761
- http://secunia.com/advisories/33923
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-125276-08-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-251086-1
- http://www.securityfocus.com/bid/33761



