Vulnerabilities > CVE-2009-4442 - Configuration vulnerability in SUN Java System Directory Server
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Directory Proxy Server (DPS) in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 does not properly implement the max-client-connections configuration setting, which allows remote attackers to cause a denial of service (connection slot exhaustion) by making multiple connections and performing no operations on these connections, aka Bug Id 6648665.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 5 |
Common Weakness Enumeration (CWE)
Nessus
NASL family | Misc. |
NASL id | SUN_DIRECTORY_PROXY_SERVER_MULTIPLE.NASL |
description | The remote host is running the Sun Java System Directory Proxy Server, an LDAP application-layer protocol gateway. It is typically provided with Sun Java System Directory Server Enterprise Edition. The installed version of Sun Java System Directory Proxy Server is older than 6.3.1.1 and thus affected by multiple flaws : - Under certain conditions, simultaneous long binds are incorrectly assigned the same back-end connection. An attacker may exploit this vulnerability to hijack an authenticated user |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 43615 |
published | 2009-12-30 |
reporter | This script is Copyright (C) 2009-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/43615 |
title | Sun Java System Directory Proxy Server 6.x < 6.3.1.1 Multiple Vulnerabilities. |
code |
|
References
- http://secunia.com/advisories/37915
- http://secunia.com/advisories/37915
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-141958-01-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-141958-01-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-270789-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-270789-1
- http://www.securityfocus.com/bid/37481
- http://www.securityfocus.com/bid/37481
- http://www.securitytracker.com/id?1023389
- http://www.securitytracker.com/id?1023389
- http://www.vupen.com/english/advisories/2009/3647
- http://www.vupen.com/english/advisories/2009/3647