Vulnerability Name: | CVE-2009-3923 (CCN-54136) | ||||||||
Assigned: | 2009-11-03 | ||||||||
Published: | 2009-11-03 | ||||||||
Updated: | 2017-08-17 | ||||||||
Summary: | The VirtualBox 2.0.8 and 2.0.10 web service in Sun Virtual Desktop Infrastructure (VDI) 3.0 does not require authentication, which allows remote attackers to obtain unspecified access via vectors involving requests to an Apache HTTP Server. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-287 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-3923 Source: CCN Type: SA37268 Sun Virtual Desktop Infrastructure VirtualBox Security Bypass Source: CONFIRM Type: Patch, Vendor Advisory http://sunsolve.sun.com/search/document.do?assetkey=1-21-141481-03-1 Source: CCN Type: Sun Alert ID: 268328 A Security Vulnerability in Sun Virtual Desktop Infrastructure (VDI) Software 3.0 may Lead to Unauthorized Access to the VirtualBox Web Service Source: SUNALERT Type: UNKNOWN 268328 Source: CCN Type: OSVDB ID: 59685 Sun Virtual Desktop Infrastructure (VDI) VirtualBox Web Service Unspecified Remote Authentication Bypass Source: BID Type: Patch 36917 Source: CCN Type: BID-36917 Sun Virtual Desktop Infrastructure Authentication Mechanism Unauthorized Access Vulnerability Source: XF Type: UNKNOWN vdi-authentication-unauth-access(54136) Source: XF Type: UNKNOWN vdi-authentication-unauth-access(54136) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |